Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Blackboard

First CVE: Jul 10, 2000Active for: 26 yearsTotal CVEs: 26
21.2
VTI Score
Low

Blackboard operates a widely deployed suite of learning-management and academic-administration platforms whose vulnerabilities, though modest in volume relative to the broader landscape, recur across a well-established product family. The exposure is rooted in web-application architecture: the disclosed weaknesses center on input-handling and session-management flaws including cross-site scripting, open redirects, cross-site request forgery, and information-disclosure issues that are typical of browser-based educational platforms. The vendor's disclosures frequently acquire public exploit tooling, making timely patching important for institutions running exposed instances. Defenders should prioritize this vendor's advisories for internet-facing learning-management deployments and track the Academic Suite and Blackboard Learn product lines as part of their educational-infrastructure inventory; current severity and exploitation details are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
5.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Blackboard over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 10, 2000
26 years ago
Most Recent CVE
Sep 5, 2022
1,419 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2002-1007HIGH
Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID para
Oct 4, 20027.529NOYES
CVE-2005-4338HIGH
announcement.pl in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to gain administrator
Dec 19, 200510.025NONO
CVE-2005-4206MEDIUM
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and condu
Dec 13, 20056.125NOYES
CVE-2022-39196MEDIUM
Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL.
Sep 5, 20226.523NONO
CVE-2020-25902MEDIUM
Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execute on the class room, which leads to stealing cookies from u
Mar 2, 20216.121NONO
CVE-2017-18262MEDIUM
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated
Apr 30, 20186.121NONO
CVE-2008-1883MEDIUM
The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attackers to access accounts via a mo
Apr 18, 20086.821NONO
CVE-2008-1795MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow remote attackers to inject arbitrary web scr
Apr 15, 20084.321NOYES
CVE-2006-4308MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote at
Aug 23, 20064.321NOYES
CVE-2020-9008MEDIUM
Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile edito
Feb 25, 20205.420NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
77%
15%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network8 (30.8%)
Unknown18 (69.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (30.8%)
High0 (0.0%)
Unknown18 (69.2%)
User Interaction
None1 (3.8%)
Unknown18 (69.2%)
Required7 (26.9%)
Privileges Required
Low4 (15.4%)
High0 (0.0%)
None4 (15.4%)
Unknown18 (69.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
15.4% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Blackboard.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Blackboard — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Blackboard's Products

View all 2 CNAs →

Top CWEs