Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dokeos

First CVE: Aug 17, 2005Active for: 21 yearsTotal CVEs: 25
34.0
VTI Score
Medium

Dokeos is an open-source learning management and e-learning platform whose vulnerability footprint, while modest in volume, reflects its role as a web-facing educational application with broad deployment potential. The vendor's disclosures cluster consistently around input-handling and injection vulnerabilities—cross-site scripting, SQL injection, code injection, and path traversal—that characterize applications processing and rendering user-supplied content without adequate sanitization. Notably, these vulnerabilities have a strong tendency to acquire public exploit code, amplifying the risk to deployed instances that lag behind security updates. Defenders should treat Dokeos deployments as requiring regular patching attention, particularly internet-accessible instances, and should monitor the vendor's release cycle for fixes to these recurrent web-layer flaws; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dokeos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 17, 2005
20 years ago
Most Recent CVE
Jan 29, 2020
2,368 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-6341HIGH
SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language parameter to index.php.
Dec 5, 20137.534NOYES
CVE-2008-0850HIGH
Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coach
Feb 21, 20087.530NOYES
CVE-2008-3363HIGH
Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and execute arbitrary local files via a ..\
Jul 30, 20087.529NOYES
CVE-2006-2284MEDIUM
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter in
May 10, 20066.829NOYES
CVE-2007-2902HIGH
SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the course parameter.
May 30, 20077.528NOYES
CVE-2007-2889HIGH
SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter.
May 30, 20077.528NOYES
CVE-2009-2009MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) curdirpath para
Jun 8, 20094.326NONO
CVE-2006-4844MEDIUM
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to ex
Sep 19, 20065.126NOYES
CVE-2009-2004HIGH
Multiple SQL injection vulnerabilities in main/mySpace/myStudents.php in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) st
Jun 8, 20097.525NONO
CVE-2008-0851MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php,
Feb 21, 20084.324NOYES
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
68%
28%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (4.0%)
Unknown24 (96.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (4.0%)
High0 (0.0%)
Unknown24 (96.0%)
User Interaction
None0 (0.0%)
Unknown24 (96.0%)
Required1 (4.0%)
Privileges Required
Low1 (4.0%)
High0 (0.0%)
None0 (0.0%)
Unknown24 (96.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
48.0% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dokeos.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dokeos — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dokeos's Products

View all 1 CNAs →

Top CWEs