Ilias is an open-source learning management system deployed across educational and organizational settings as a centralized platform for course management, content delivery, and user collaboration. The platform's vulnerability profile skews toward serious outcomes, with an elevated share reaching critical severity and a marked tendency to acquire public exploit code, reflecting both the internet-facing nature of LMS deployments and the attack surface inherent in handling user-generated content and privilege management. Exposure recurs through web-application weakness classes including cross-site scripting, unsafe deserialization, and code-injection flaws that arise from dynamic content processing and insufficient input sanitization. Defenders should prioritize patching Ilias instances, particularly those internet-exposed or handling sensitive educational data, and treat this vendor's advisories as high-priority across institutional deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ilias over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11344CRITICAL A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate Import Handler. The manipulation | Oct 6, 2025 | 9.8 | 34 | NO | NO |
CVE-2022-45917MEDIUM ILIAS before 7.16 has an Open Redirect. | Dec 7, 2022 | 6.1 | 32 | NO | YES |
CVE-2025-11345CRITICAL A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It i | Oct 6, 2025 | 9.8 | 31 | NO | NO |
CVE-2018-5688MEDIUM ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in the Setup component. | Jan 14, 2018 | 6.1 | 31 | NO | YES |
CVE-2025-11346CRITICAL A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_se | Oct 6, 2025 | 9.8 | 30 | NO | NO |
CVE-2008-5816HIGH SQL injection vulnerability in repository.php in ILIAS 3.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ref_id parameter. | Jan 2, 2009 | 7.5 | 28 | NO | YES |
CVE-2023-36487CRITICAL The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account. | Jun 29, 2023 | 9.8 | 27 | NO | NO |
CVE-2014-2089MEDIUM ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .php file with a certain client_id pathname. | Mar 2, 2014 | 6.8 | 27 | NO | YES |
CVE-2023-45869CRITICAL ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The injecte | Oct 26, 2023 | 9.0 | 26 | NO | NO |
CVE-2020-23996HIGH A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data. | May 13, 2021 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ilias.
Media articles that mention a CVE ID that affects a product developed by Ilias — matched by CVE ID, not by vendor name.