Jatos is a research-platform framework for designing and running online behavioral studies, presenting a narrowly scoped but prominently deployed product in the academic and experimental-research space. The vendor's disclosed vulnerabilities cluster around web-application security fundamentals: cross-site request forgery, cross-site scripting, path traversal, and improper authentication-attempt limiting—weaknesses endemic to web frameworks handling user sessions and file access. Defenders deploying this platform should prioritize input validation and session-management controls; live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jatos over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-55008HIGH JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeatedl | Jan 7, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-51382HIGH Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw can result in unauthorized acc | Nov 5, 2024 | 8.4 | 22 | NO | NO |
CVE-2024-51381HIGH Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critic | Nov 5, 2024 | 8.4 | 22 | NO | NO |
CVE-2024-51380HIGH Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows an attacker to inject malicious JavaScript into the propert | Nov 5, 2024 | 8.4 | 22 | NO | NO |
CVE-2024-51379HIGH Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject | Nov 5, 2024 | 8.4 | 22 | NO | NO |
CVE-2022-4878MEDIUM A vulnerability classified as critical has been found in JATOS. Affected is the function ZipUtil of the file modules/common/app/utils/common/ZipUtil.java of the component ZIP Handl | Jan 6, 2023 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jatos.
Media articles that mention a CVE ID that affects a product developed by Jatos — matched by CVE ID, not by vendor name.