Loris
Aces · 11 CVEs
LORIS has an open redirect field on login
Apr 9, 2026
LORIS has a path traversal in FilesDownloadHandler
Apr 8, 2026
LORIS has potential cross-site scripting in survey_accounts module
Apr 8, 2026
LORIS incorrectly trusts user input in publication module
Apr 8, 2026
LORIS has potential cross-site scripting in help_editor module
Apr 8, 2026
LORIS has incorrect access checks in document_repository
Apr 8, 2026
LORIS has incorrect access checks in media module
Apr 8, 2026
LORIS has a path traversal in static router
Apr 8, 2026
LORIS has a SQL injection in MRI feedback popup
Apr 8, 2026
LORIS vulnerable to path traversal in electrophysiology_browser
Feb 25, 2026
LORIS media module vulnerable to remote code execution
Feb 25, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-39985 | LORIS has an open redirect field on login | MEDIUM | 0.35% | Apr 9, 2026 |
| CVE-2026-35446 | LORIS has a path traversal in FilesDownloadHandler | HIGH | 0.38% | Apr 8, 2026 |
| CVE-2026-35403 | LORIS has potential cross-site scripting in survey_accounts module | MEDIUM | 0.22% | Apr 8, 2026 |
| CVE-2026-35400 | LORIS incorrectly trusts user input in publication module | MEDIUM | 0.30% | Apr 8, 2026 |
| CVE-2026-35169 | LORIS has potential cross-site scripting in help_editor module | HIGH | 0.27% | Apr 8, 2026 |
| CVE-2026-35165 | LORIS has incorrect access checks in document_repository | MEDIUM | 0.27% | Apr 8, 2026 |
| CVE-2026-34985 | LORIS has incorrect access checks in media module | MEDIUM | 0.27% | Apr 8, 2026 |
| CVE-2026-34392 | LORIS has a path traversal in static router | HIGH | 0.42% | Apr 8, 2026 |
| CVE-2026-33350 | LORIS has a SQL injection in MRI feedback popup | HIGH | 0.41% | Apr 8, 2026 |
| CVE-2026-26985 | LORIS vulnerable to path traversal in electrophysiology_browser | HIGH | 0.52% | Feb 25, 2026 |
| CVE-2026-26984 | LORIS media module vulnerable to remote code execution | HIGH | 1.07% | Feb 25, 2026 |
Showing 1 to 11 of 11 CVEs