Claroline is an open-source learning management platform whose vulnerability footprint concentrates in a single product serving educational institutions. The vendor's disclosures reflect the attack surface inherent to a web-based educational application: recurrent weaknesses center on input validation and output encoding (cross-site scripting), session and state management (CSRF), and code-injection vectors, alongside exposures of sensitive educational or user data. Public exploit code has frequently been available for Claroline vulnerabilities, making timely patching essential for institutions relying on the platform. Defenders operating Claroline instances should prioritize updates and supplement network controls with web-application firewalls; live severity and current exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Claroline over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37159CRITICAL Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload. | Aug 25, 2022 | 9.8 | 41 | NO | NO |
CVE-2006-7048HIGH Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter to | Feb 24, 2007 | 7.5 | 29 | NO | YES |
CVE-2006-5256HIGH PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the in | Oct 12, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-2284MEDIUM Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter in | May 10, 2006 | 6.8 | 29 | NO | YES |
CVE-2005-1375HIGH Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) lea | May 3, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-1374MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to inject arbitrary web script o | May 3, 2005 | 6.8 | 28 | NO | YES |
CVE-2006-2868MEDIUM Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the includePath cookie to (1) auth/extauth/d | Jun 6, 2006 | 5.1 | 27 | NO | YES |
CVE-2006-4844MEDIUM PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to ex | Sep 19, 2006 | 5.1 | 26 | NO | YES |
CVE-2007-4718MEDIUM Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in t | Sep 5, 2007 | 5.1 | 25 | NO | YES |
CVE-2006-0411HIGH claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain adminis | Jan 25, 2006 | 10.0 | 25 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Claroline.
Media articles that mention a CVE ID that affects a product developed by Claroline — matched by CVE ID, not by vendor name.