Duraspace develops a focused portfolio of digital preservation and repository platforms, including DSpace and Vitro, that serve academic and cultural institutions for long-term content stewardship. The vendor's vulnerability exposure centers on application-layer input handling and access control, with recurring weaknesses including path traversal, cross-site scripting, improper authorization, and sensitive-information disclosure that are characteristic of web-based repository systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Duraspace over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41189HIGH DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. | Oct 29, 2021 | 7.2 | 25 | NO | NO |
CVE-2019-6986HIGH SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as dem | Jan 28, 2019 | 7.5 | 25 | NO | NO |
CVE-2016-10726HIGH The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a | Jul 10, 2018 | 7.5 | 23 | NO | NO |
CVE-2022-31195HIGH DSpace open source software is a repository application which provides durable access to digital resources. In affected versions the ItemImportServiceImpl is vulnerable to a path t | Aug 1, 2022 | 7.2 | 22 | NO | NO |
CVE-2022-31194HIGH DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI resumable upload im | Aug 1, 2022 | 7.2 | 22 | NO | NO |
CVE-2022-31193MEDIUM DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI controlled vocabula | Aug 1, 2022 | 6.1 | 20 | NO | NO |
CVE-2022-31192MEDIUM DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" fe | Aug 1, 2022 | 6.1 | 20 | NO | NO |
CVE-2022-31189MEDIUM DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. When an "Internal System Erro | Aug 1, 2022 | 5.3 | 19 | NO | NO |
CVE-2022-31190MEDIUM DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata | Aug 1, 2022 | 5.3 | 19 | NO | NO |
CVE-2022-31191MEDIUM DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI spellcheck "Did you | Aug 1, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Duraspace.
Media articles that mention a CVE ID that affects a product developed by Duraspace — matched by CVE ID, not by vendor name.