Eskooly is an educational management platform with a narrow but prominent footprint, where its vulnerability disclosures concentrate in a single product and skew strongly toward critical-severity outcomes. The recurring weakness pattern—spanning improper privilege management, cross-site request forgery, protection mechanism failure, and unverified password change—points to authentication and authorization gaps characteristic of web-based administrative and student-data systems. Defenders managing educational infrastructure should prioritize patch cycles for this platform; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eskooly over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27712CRITICAL An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the User Account Mangemnt component in the authentic | Jul 5, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-27710CRITICAL An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authentication mechanism. | Jul 5, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-27711HIGH An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up process function in the account settings. | Jul 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-27715HIGH An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted request to the Password Change mechanism. | Jul 5, 2024 | 8.2 | 23 | NO | NO |
CVE-2024-27713HIGH An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP Response Header Settings component. | Jul 5, 2024 | 8.8 | 22 | NO | NO |
CVE-2024-27717MEDIUM Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a remote attacker to escalate privileges via the Token Handling c | Jul 5, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eskooly.
Media articles that mention a CVE ID that affects a product developed by Eskooly — matched by CVE ID, not by vendor name.