Cnvs maintains Canvas, a learning management and collaboration platform whose vulnerability disclosures have centered on cross-site scripting issues arising from improper input neutralization in web-facing components. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cnvs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000507MEDIUM Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in denial of service and execution of javascript code. | Feb 9, 2018 | 5.4 | 18 | NO | NO |
CVE-2017-8298MEDIUM cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a "Posts > Add New" action, and during creation of new tags and users. | Apr 27, 2017 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cnvs.
Media articles that mention a CVE ID that affects a product developed by Cnvs — matched by CVE ID, not by vendor name.