Daycloud's vulnerability profile centers on its StudentManage product, a student information system where the observed weaknesses cluster around web application input handling and authentication boundaries. The recurring exposure involves cross-site scripting, cross-site request forgery, and SQL injection, which are characteristic risks in data-entry and form-heavy applications that process student records and institutional data; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Daycloud over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50585HIGH StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl. | Jul 18, 2025 | 8.8 | 26 | NO | NO |
CVE-2025-50586MEDIUM StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF). | Jul 18, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-50582MEDIUM StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module. | Jul 18, 2025 | 4.8 | 18 | NO | NO |
CVE-2025-50584MEDIUM StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module. | Jul 18, 2025 | 4.8 | 18 | NO | NO |
CVE-2025-50583MEDIUM StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module. | Jul 18, 2025 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Daycloud.
Media articles that mention a CVE ID that affects a product developed by Daycloud — matched by CVE ID, not by vendor name.