Instructure develops Canvas, a widely deployed learning-management platform that mediates authentication and resource access across educational institutions. The vulnerability exposure concentrates in this core product and centers on weaknesses in authorization enforcement and server-side request handling, reflecting the authentication and access-control demands of a multi-tenant education platform. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Instructure over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-5775MEDIUM Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains. | Aug 21, 2020 | 5.8 | 26 | NO | YES |
CVE-2021-36539MEDIUM Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url). | Jan 26, 2023 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Instructure.
Media articles that mention a CVE ID that affects a product developed by Instructure — matched by CVE ID, not by vendor name.