Eprints is a niche open-source institutional repository platform whose vulnerability footprint, though small in volume, spans a single widely deployed product used by academic and research institutions. The vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with the recurring weakness classes—OS command injection, cross-site scripting, and XML external entity reference flaws—reflecting the parsing and input-handling demands of a web-based document management system. Defenders managing Eprints instances should prioritize patching and treat this platform as a sensitive target given its role in institutional data access; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eprints over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26475MEDIUM EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI. | Mar 1, 2021 | 6.1 | 32 | NO | YES |
CVE-2021-3342CRITICAL EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI. | Mar 1, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-26703CRITICAL EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI. | Mar 1, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-26702MEDIUM EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI. | Mar 1, 2021 | 6.1 | 30 | NO | YES |
CVE-2021-26476CRITICAL EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI. | Mar 1, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-26704HIGH EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI. | Mar 1, 2021 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eprints.
Media articles that mention a CVE ID that affects a product developed by Eprints — matched by CVE ID, not by vendor name.