Apereo develops open-source software serving higher-education and institutional identity and access management, with a focused portfolio anchored by products such as OpenCast, Central Authentication Service, phpCAS, and calendar and WebDAV engines that are embedded across academic infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the authentication-critical and data-handling roles these systems play in campus networks. The exposure recurs across this product line through weakness classes including improper authentication, exposure of sensitive information, injection flaws, cross-site scripting, and XML external entity vulnerabilities—patterns characteristic of web-facing identity and media-management systems handling institutional credentials and student records. Defenders should prioritize patching within the authentication and directory-facing tier and audit integration points where these systems interface with institutional repositories and student-information systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apereo over time
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32985CRITICAL Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to | Mar 20, 2026 | 9.8 | 44 | NO | YES |
CVE-2024-4399CRITICAL The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack | May 23, 2024 | 9.1 | 39 | NO | YES |
CVE-2021-42567MEDIUM Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints. | Dec 7, 2021 | 6.1 | 35 | NO | YES |
CVE-2014-4172CRITICAL A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2 | Jan 24, 2020 | 9.8 | 33 | NO | NO |
CVE-2023-4612CRITICAL Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS | Nov 9, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-5206CRITICAL In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that user even if the remember-me cooki | Jan 30, 2020 | 10.0 | 29 | NO | NO |
CVE-2022-39369HIGH phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP header | Nov 1, 2022 | 8.0 | 27 | NO | NO |
CVE-2019-10754HIGH Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to | Sep 23, 2019 | 8.1 | 27 | NO | NO |
CVE-2018-1000836CRITICAL bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can result in Disclosure of confidenti | Dec 20, 2018 | 9.0 | 26 | NO | NO |
CVE-2024-11208HIGH A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads t | Nov 14, 2024 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apereo.
Media articles that mention a CVE ID that affects a product developed by Apereo — matched by CVE ID, not by vendor name.