The HISP Centre at the University of Oslo maintains DHIS 2, a health information management platform widely deployed across public health systems in resource-limited settings, which despite a narrow product focus carries significance within its epidemiological and surveillance domain. The recurring vulnerability patterns center on application-layer input handling and access control, with disclosures clustering around SQL injection, cross-site scripting, improper authorization, and privilege management weaknesses that are characteristic of web-facing data-collection systems. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by The HISP Centre at the University of Oslo over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24848HIGH DHIS2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability affects the `/api/programs/orgUnits?pro | Jun 1, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-41187HIGH DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of | Nov 1, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-39179HIGH DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL Injection vulnerability in the Tracker component in DHIS2 Server allows | Oct 29, 2021 | 8.8 | 27 | NO | NO |
CVE-2022-41948HIGH DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Affected versions are subject to a privilege escalation vulnerabi | Dec 8, 2022 | 7.2 | 24 | NO | NO |
CVE-2021-32704HIGH DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of | Jun 24, 2021 | 8.8 | 24 | NO | NO |
CVE-2023-31139HIGH DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.37 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39. | May 9, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-32060MEDIUM DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.35 branch and prior to versions 2.36.13, 2.37.8, 2.38.2, and | May 9, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-31138MEDIUM DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.36 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39. | May 9, 2023 | 6.5 | 21 | NO | NO |
CVE-2022-41947MEDIUM DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Through various features of DHIS2, an authenticated user may be a | Dec 8, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-41949MEDIUM DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. In affected versions an authenticated DHIS2 user can craft a requ | Dec 8, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by The HISP Centre at the University of Oslo.
Media articles that mention a CVE ID that affects a product developed by The HISP Centre at the University of Oslo — matched by CVE ID, not by vendor name.