Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Apereo

First CVE: Oct 7, 2010Active for: 16 yearsTotal CVEs: 46
43.1
VTI Score
High

Apereo develops open-source software serving higher-education and institutional identity and access management, with a focused portfolio anchored by products such as OpenCast, Central Authentication Service, phpCAS, and calendar and WebDAV engines that are embedded across academic infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the authentication-critical and data-handling roles these systems play in campus networks. The exposure recurs across this product line through weakness classes including improper authentication, exposure of sensitive information, injection flaws, cross-site scripting, and XML external entity vulnerabilities—patterns characteristic of web-facing identity and media-management systems handling institutional credentials and student records. Defenders should prioritize patching within the authentication and directory-facing tier and audit integration points where these systems interface with institutional repositories and student-information systems. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
46
Total CVEs
More Total CVEs than 98% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Apereo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2010
15 years ago
Most Recent CVE
Mar 20, 2026
127 days ago

Products(9 total)

Top CVEs

Signals from CVEs in this vendor scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-32985CRITICAL
Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to
Mar 20, 20269.844NOYES
CVE-2024-4399CRITICAL
The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack
May 23, 20249.139NOYES
CVE-2021-42567MEDIUM
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
Dec 7, 20216.135NOYES
CVE-2014-4172CRITICAL
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2
Jan 24, 20209.833NONO
CVE-2023-4612CRITICAL
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS
Nov 9, 20239.830NONO
CVE-2020-5206CRITICAL
In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that user even if the remember-me cooki
Jan 30, 202010.029NONO
CVE-2022-39369HIGH
phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP header
Nov 1, 20228.027NONO
CVE-2019-10754HIGH
Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to
Sep 23, 20198.127NONO
CVE-2018-1000836CRITICAL
bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can result in Disclosure of confidenti
Dec 20, 20189.026NONO
CVE-2024-11208HIGH
A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads t
Nov 14, 20248.125NONO
View all 46 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products46 CVEs
43%
39%
15%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.2%)
Network40 (87.0%)
Unknown5 (10.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (78.3%)
High5 (10.9%)
Unknown5 (10.9%)
User Interaction
None33 (71.7%)
Unknown5 (10.9%)
Required8 (17.4%)
Privileges Required
Low17 (37.0%)
High1 (2.2%)
None23 (50.0%)
Unknown5 (10.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (46 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.2% of CVEs· 97th percentile
Nuclei
2 CVEs
4.3% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Apereo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Apereo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Apereo's Products

View all 8 CNAs →

Top CWEs