Epignosishq develops the eFront learning management system, a platform deployed across educational and enterprise training environments, where its vulnerability footprint clusters around untrusted deserialization, SQL injection, and cryptographic-seed weaknesses that reflect risks in user-input handling and cryptographic initialization. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Epignosishq over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5069HIGH A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being exec | Sep 5, 2019 | 8.8 | 28 | NO | NO |
CVE-2020-28597HIGH A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password re | Mar 3, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-5070MEDIUM An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause | Sep 5, 2019 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Epignosishq.
Media articles that mention a CVE ID that affects a product developed by Epignosishq — matched by CVE ID, not by vendor name.