Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Claroline

First CVE: May 3, 2005Active for: 21 yearsTotal CVEs: 31
44.9
VTI Score
High

Claroline is an open-source learning management platform whose vulnerability footprint concentrates in a single product serving educational institutions. The vendor's disclosures reflect the attack surface inherent to a web-based educational application: recurrent weaknesses center on input validation and output encoding (cross-site scripting), session and state management (CSRF), and code-injection vectors, alongside exposures of sensitive educational or user data. Public exploit code has frequently been available for Claroline vulnerabilities, making timely patching essential for institutions relying on the platform. Defenders operating Claroline instances should prioritize updates and supplement network controls with web-application firewalls; live severity and current exploitation activity are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
3.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Claroline over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 3, 2005
21 years ago
Most Recent CVE
Aug 25, 2022
1,429 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-37159CRITICAL
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
Aug 25, 20229.841NONO
CVE-2006-7048HIGH
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter to
Feb 24, 20077.529NOYES
CVE-2006-5256HIGH
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the in
Oct 12, 20067.529NOYES
CVE-2006-2284MEDIUM
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter in
May 10, 20066.829NOYES
CVE-2005-1375HIGH
Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) lea
May 3, 20057.529NOYES
CVE-2005-1374MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to inject arbitrary web script o
May 3, 20056.828NOYES
CVE-2006-2868MEDIUM
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the includePath cookie to (1) auth/extauth/d
Jun 6, 20065.127NOYES
CVE-2006-4844MEDIUM
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to ex
Sep 19, 20065.126NOYES
CVE-2007-4718MEDIUM
Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in t
Sep 5, 20075.125NOYES
CVE-2006-0411HIGH
claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain adminis
Jan 25, 200610.025NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
10%
61%
26%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (12.9%)
Unknown27 (87.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (12.9%)
High0 (0.0%)
Unknown27 (87.1%)
User Interaction
None1 (3.2%)
Unknown27 (87.1%)
Required3 (9.7%)
Privileges Required
Low2 (6.5%)
High0 (0.0%)
None2 (6.5%)
Unknown27 (87.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
15 CVEs
48.4% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Claroline.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Claroline — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Claroline's Products

View all 1 CNAs →

Top CWEs