Easy Student Results Project maintains a focused educational results-management application, with the observed vulnerability exposure centered on web application input handling and access control. The recurring weaknesses—cross-site scripting in page generation and missing authorization checks—are characteristic of web-facing applications that process and display student data without sufficient input validation and permission enforcement. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easy Student Results Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2379HIGH The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, d | Aug 15, 2022 | 7.5 | 30 | NO | YES |
CVE-2022-2378MEDIUM The Easy Student Results WordPress plugin through 2.2.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | Aug 15, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easy Student Results Project.
Media articles that mention a CVE ID that affects a product developed by Easy Student Results Project — matched by CVE ID, not by vendor name.