Evergreen Ils is an open-source integrated library system that manages cataloging, circulation, and patron services for academic and public libraries; its vulnerability exposure is narrowly scoped to the Evergreen product itself. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Evergreen Ils over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7435MEDIUM The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by levera | Feb 1, 2018 | 6.5 | 23 | NO | NO |
CVE-2015-2204HIGH Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit | Feb 1, 2018 | 7.5 | 20 | NO | NO |
CVE-2015-2203MEDIUM Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.p | Feb 1, 2018 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Evergreen Ils.
Media articles that mention a CVE ID that affects a product developed by Evergreen Ils — matched by CVE ID, not by vendor name.