Efrontlearning develops a learning management platform centered around its Efront product line, deployed across educational and corporate training environments. The vendor's vulnerability profile centers on recurrent web-application weaknesses—cross-site scripting, path traversal, unrestricted file uploads, information disclosure, and code injection—that are characteristic of server-side application handling of user input and file operations, and the portfolio shows an elevated tendency toward public exploit availability. Defenders should prioritize patching for this vendor's disclosures affecting internet-facing instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Efrontlearning over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1918HIGH SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter. | May 12, 2010 | 7.5 | 29 | NO | YES |
CVE-2010-1003MEDIUM Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a | Mar 19, 2010 | 6.8 | 28 | NO | YES |
CVE-2009-3660MEDIUM PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP co | Oct 11, 2009 | 6.8 | 28 | NO | YES |
CVE-2008-7026MEDIUM Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an | Aug 21, 2009 | 6.8 | 28 | NO | YES |
CVE-2012-1048MEDIUM Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to in | Feb 12, 2012 | 4.3 | 26 | NO | YES |
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script | Dec 21, 2013 | 3.5 | 24 | NO | YES |
CVE-2014-4033MEDIUM Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arbitrary web script or HTML via | Jun 11, 2014 | 4.3 | 22 | NO | YES |
CVE-2012-4269MEDIUM Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension via an attachme | Aug 13, 2012 | 6.0 | 19 | NO | NO |
CVE-2012-6515MEDIUM eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson_info module to index.php, whic | Jan 24, 2013 | 5.0 | 18 | NO | NO |
CVE-2015-4461MEDIUM Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter. | Feb 5, 2018 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Efrontlearning.
Media articles that mention a CVE ID that affects a product developed by Efrontlearning — matched by CVE ID, not by vendor name.