Blackboard operates a widely deployed suite of learning-management and academic-administration platforms whose vulnerabilities, though modest in volume relative to the broader landscape, recur across a well-established product family. The exposure is rooted in web-application architecture: the disclosed weaknesses center on input-handling and session-management flaws including cross-site scripting, open redirects, cross-site request forgery, and information-disclosure issues that are typical of browser-based educational platforms. The vendor's disclosures frequently acquire public exploit tooling, making timely patching important for institutions running exposed instances. Defenders should prioritize this vendor's advisories for internet-facing learning-management deployments and track the Academic Suite and Blackboard Learn product lines as part of their educational-infrastructure inventory; current severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blackboard over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1007HIGH Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID para | Oct 4, 2002 | 7.5 | 29 | NO | YES |
CVE-2005-4338HIGH announcement.pl in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to gain administrator | Dec 19, 2005 | 10.0 | 25 | NO | NO |
CVE-2005-4206MEDIUM Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and condu | Dec 13, 2005 | 6.1 | 25 | NO | YES |
CVE-2022-39196MEDIUM Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL. | Sep 5, 2022 | 6.5 | 23 | NO | NO |
CVE-2020-25902MEDIUM Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execute on the class room, which leads to stealing cookies from u | Mar 2, 2021 | 6.1 | 21 | NO | NO |
CVE-2017-18262MEDIUM Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated | Apr 30, 2018 | 6.1 | 21 | NO | NO |
CVE-2008-1883MEDIUM The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attackers to access accounts via a mo | Apr 18, 2008 | 6.8 | 21 | NO | NO |
CVE-2008-1795MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow remote attackers to inject arbitrary web scr | Apr 15, 2008 | 4.3 | 21 | NO | YES |
CVE-2006-4308MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote at | Aug 23, 2006 | 4.3 | 21 | NO | YES |
CVE-2020-9008MEDIUM Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile edito | Feb 25, 2020 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blackboard.
Media articles that mention a CVE ID that affects a product developed by Blackboard — matched by CVE ID, not by vendor name.