Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Markusproject

First CVE: Nov 18, 2024Active for: 2 yearsTotal CVEs: 8

Markusproject maintains Markus, an academic course-management and assignment-grading platform, with a vulnerability profile concentrated on this single product. Vulnerabilities affecting the platform skew toward serious outcomes and recur through web-application and file-handling weakness classes including unrestricted file uploads, authorization bypasses tied to user-controlled keys, path traversal, cross-site scripting, and improper handling of compressed data—issues characteristic of systems that process student submissions and manage access controls. Defenders deploying Markus in production should prioritize patching and restrict file-upload permissions; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Markusproject over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2024
20 months ago
Most Recent CVE
Mar 6, 2026
140 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-25057CRITICAL
MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able to upload a zip file to create an assignment from an exporte
Feb 9, 20269.130NONO
CVE-2024-51743HIGH
MarkUs is a web application for the submission and grading of student assignments. In versions prior to 2.4.8, an arbitrary file write vulnerability in the update/upload/create fil
Nov 18, 20248.825NONO
CVE-2024-51499HIGH
MarkUs is a web application for the submission and grading of student assignments. In versions prior to 2.4.8, an arbitrary file write vulnerability accessible via the update_files
Nov 18, 20248.824NONO
CVE-2026-25962MEDIUM
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs currently extracts zip files without any size or entry-count limit
Mar 6, 20266.522NONO
CVE-2026-24900MEDIUM
MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, the courses/<:course_id>/assignments/<:assignment_id>/submissions/html_content ac
Feb 9, 20266.522NONO
CVE-2026-28405MEDIUM
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.1, the courses/<:course_id>/assignments/<:assignment_id>/submissions/html_co
Mar 5, 20265.419NONO
CVE-2026-27807MEDIUM
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows course instructors to upload YAML files to create/update va
Mar 6, 20264.918NONO
CVE-2024-47820LOW
MarkUs, a web application for the submission and grading of student assignments, is vulnerable to path traversal in versions prior to 2.4.8. Authenticated instructors may download
Nov 18, 20243.515NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
13%
50%
25%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (12.5%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low5 (62.5%)
High3 (37.5%)
None0 (0.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Markusproject.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Markusproject — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Markusproject's Products

View all 1 CNAs →

Top CWEs