Dokeos is an open-source learning management and e-learning platform whose vulnerability footprint, while modest in volume, reflects its role as a web-facing educational application with broad deployment potential. The vendor's disclosures cluster consistently around input-handling and injection vulnerabilities—cross-site scripting, SQL injection, code injection, and path traversal—that characterize applications processing and rendering user-supplied content without adequate sanitization. Notably, these vulnerabilities have a strong tendency to acquire public exploit code, amplifying the risk to deployed instances that lag behind security updates. Defenders should treat Dokeos deployments as requiring regular patching attention, particularly internet-accessible instances, and should monitor the vendor's release cycle for fixes to these recurrent web-layer flaws; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dokeos over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-6341HIGH SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language parameter to index.php. | Dec 5, 2013 | 7.5 | 34 | NO | YES |
CVE-2008-0850HIGH Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coach | Feb 21, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-3363HIGH Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and execute arbitrary local files via a ..\ | Jul 30, 2008 | 7.5 | 29 | NO | YES |
CVE-2006-2284MEDIUM Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter in | May 10, 2006 | 6.8 | 29 | NO | YES |
CVE-2007-2902HIGH SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the course parameter. | May 30, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-2889HIGH SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter. | May 30, 2007 | 7.5 | 28 | NO | YES |
CVE-2009-2009MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) curdirpath para | Jun 8, 2009 | 4.3 | 26 | NO | NO |
CVE-2006-4844MEDIUM PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to ex | Sep 19, 2006 | 5.1 | 26 | NO | YES |
CVE-2009-2004HIGH Multiple SQL injection vulnerabilities in main/mySpace/myStudents.php in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) st | Jun 8, 2009 | 7.5 | 25 | NO | NO |
CVE-2008-0851MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, | Feb 21, 2008 | 4.3 | 24 | NO | YES |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dokeos.
Media articles that mention a CVE ID that affects a product developed by Dokeos — matched by CVE ID, not by vendor name.