Frentix maintains OpenOLAT, an open-source learning management system widely deployed in educational institutions, where its vulnerability profile centers on web-application security boundaries. Vulnerabilities affecting the platform skew toward serious outcomes, with path traversal, input validation, cross-site scripting, and authentication weaknesses recurring across the codebase—weakness classes characteristic of the challenge of securing user-facing web applications handling institutional data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frentix over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31946CRITICAL OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version 20.2.5, OpenOLAT's OpenID Conne | Mar 30, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-28228HIGH OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to versions 19.1.31, 20.1.18, and 20.2.5, an authenticated user | Mar 30, 2026 | 8.8 | 30 | NO | NO |
CVE-2021-39181HIGH OpenOlat is a web-based learning management system (LMS). Prior to version 15.3.18, 15.5.3, and 16.0.0, using a prepared import XML file (e.g. a course) any class on the Java class | Sep 1, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-39180HIGH OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Using a specially prepared ZIP fil | Aug 31, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-41242HIGH OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a r | Dec 10, 2021 | 8.1 | 27 | NO | NO |
CVE-2021-41152HIGH OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected versions by manipulating the HTT | Oct 18, 2021 | 7.7 | 24 | NO | NO |
CVE-2024-28198HIGH OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests when using the draw.io integra | Mar 11, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-25974MEDIUM The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of OpenOlat version 18.1.5 (o | Feb 20, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-25973MEDIUM The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create a course with a | Feb 20, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frentix.
Media articles that mention a CVE ID that affects a product developed by Frentix — matched by CVE ID, not by vendor name.