Openeclass
Openeclass · 8 CVEs
An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11,…
Mar 16, 2026
Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)
Jan 8, 2026
Open eClass Platform allows Arbitrary File Upload in "modules/h5p/save.php"
Aug 12, 2024
Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authe…
Jun 13, 2024
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fi…
Jun 13, 2024
Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to…
Mar 14, 2024
An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 an…
Jun 27, 2022
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to ins…
Apr 1, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-65734 | An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, allows attackers to… | MEDIUM | 0.24% | Mar 16, 2026 |
| CVE-2026-22241 | Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE) | HIGH | 3.26% | Jan 8, 2026 |
| CVE-2024-38530 | Open eClass Platform allows Arbitrary File Upload in "modules/h5p/save.php" | CRITICAL | 0.78% | Aug 12, 2024 |
| CVE-2024-33253 | Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authenticated privileged attacker to execute… | MEDIUM | 0.41% | Jun 13, 2024 |
| CVE-2024-31777 | File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint. | CRITICAL | 3.82% | Jun 13, 2024 |
| CVE-2024-26503 | Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code via upload of crafte… | CRITICAL | 1.13% | Mar 14, 2024 |
| CVE-2022-33116 | An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attackers to read arbitra… | MEDIUM | 1.77% | Jun 27, 2022 |
| CVE-2017-7389 | Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient filtration of user-supplied da… | MEDIUM | 0.84% | Apr 1, 2017 |
Showing 1 to 8 of 8 CVEs