Open Eclass Platform
Vendor:
First CVE: Aug 19, 2020 · Active for 5 years
20
Total CVEs
More Total CVEs than 94% of tracked products
6.7
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Open Eclass Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 19, 2020
5 years ago
Most Recent CVE
Feb 3, 2026
171 days ago
CVE Severity & Scoring
Open Eclass Platform20 CVEs
75%
25%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (5.0%)
Network19 (95.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (95.0%)
High1 (5.0%)
Unknown0 (0.0%)
User Interaction
None13 (65.0%)
Unknown0 (0.0%)
Required7 (35.0%)
Privileges Required
Low10 (50.0%)
High2 (10.0%)
None8 (40.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-37113HIGH GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web | Feb 3, 2026 | 8.8 | 27 | NO | NO |
CVE-2020-37116HIGH GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploadin | Feb 3, 2026 | 8.8 | 25 | NO | NO |
CVE-2026-24669HIGH The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an insecure password reset mechanism allows local attackers | Feb 3, 2026 | 7.8 | 23 | NO | NO |
CVE-2021-44266MEDIUM GUnet Open eClass (aka openeclass) before 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter. | Jun 11, 2022 | 6.1 | 23 | NO | NO |
CVE-2020-24381HIGH GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks d | Aug 19, 2020 | 7.5 | 23 | NO | NO |
CVE-2026-24773HIGH The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an Insecure Direct Object Reference (IDOR) vulnerability all | Feb 3, 2026 | 7.5 | 22 | NO | NO |
CVE-2026-24670MEDIUM The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated s | Feb 3, 2026 | 6.5 | 20 | NO | NO |
CVE-2026-24668MEDIUM The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated s | Feb 3, 2026 | 6.5 | 20 | NO | NO |
CVE-2026-24666MEDIUM The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Cross-Site Request Forgery (CSRF) vulnerability in multipl | Feb 3, 2026 | 6.5 | 20 | NO | NO |
CVE-2026-24665MEDIUM The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a stored Cross-Site Scripting (XSS) vulnerability allows aut | Feb 3, 2026 | 5.4 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Open Eclass Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.7.3 | 5 | 7.1 | 0.4% | 0 | 0 |