Arox develops a focused line of school management and enterprise resource planning software built on PHP and MySQL, a popular but security-intensive stack for educational institutions. The vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrating across recurring weakness classes including unrestricted file uploads, cross-site scripting, SQL injection, cross-site request forgery, and improper authentication—vulnerabilities endemic to web applications handling sensitive student and administrative data. Defenders deploying Arox products should treat updates as high-priority and assume public tooling exists for disclosed flaws; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arox over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13294CRITICAL AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command | Jul 4, 2019 | 9.8 | 52 | NO | YES |
CVE-2017-15978CRITICAL AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter. | Oct 31, 2017 | 9.8 | 40 | NO | YES |
CVE-2020-37090CRITICAL School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts throu | Feb 3, 2026 | 9.8 | 30 | NO | NO |
CVE-2020-8505MEDIUM School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user. | Jan 31, 2020 | 6.5 | 30 | NO | YES |
CVE-2020-8504MEDIUM School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user. | Jan 31, 2020 | 6.5 | 30 | NO | YES |
CVE-2020-37089CRITICAL School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries through GET requests. Attackers can | Feb 3, 2026 | 9.8 | 29 | NO | NO |
CVE-2022-32119HIGH Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel fu | Jul 15, 2022 | 8.8 | 29 | NO | NO |
CVE-2020-37088HIGH School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. | Feb 3, 2026 | 7.5 | 26 | NO | NO |
CVE-2024-4824CRITICAL Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucheri | May 14, 2024 | 9.8 | 25 | NO | NO |
CVE-2020-37084HIGH School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension | Feb 3, 2026 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arox.
Media articles that mention a CVE ID that affects a product developed by Arox — matched by CVE ID, not by vendor name.