McGill's vulnerability footprint centers on LORIS, a research data management platform, where disclosures concentrate on access-control and input-handling weaknesses including authorization bypass through user-controlled keys, path traversal, cross-site scripting, and exposure of files and directories to external parties. These patterns reflect the platform's role in managing sensitive research data and underscore the importance of access control and input validation in systems handling restricted information. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mcgill over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26984HIGH LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to versions 26. | Feb 25, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-35446HIGH LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before | Apr 8, 2026 | 8.6 | 29 | NO | NO |
CVE-2026-34392HIGH LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before | Apr 8, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-33350HIGH LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 2 | Apr 8, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-26985MEDIUM LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Starting in version 2 | Feb 25, 2026 | 6.5 | 24 | NO | NO |
CVE-2026-35165MEDIUM LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 21.0.0 to before | Apr 8, 2026 | 6.5 | 23 | NO | NO |
CVE-2026-34985MEDIUM LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 16.1.0 to before | Apr 8, 2026 | 6.5 | 23 | NO | NO |
CVE-2026-35169MEDIUM LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0. | Apr 8, 2026 | 5.4 | 22 | NO | NO |
CVE-2026-39985MEDIUM LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 2 | Apr 9, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-35403MEDIUM LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 15.10 to before | Apr 8, 2026 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mcgill.
Media articles that mention a CVE ID that affects a product developed by Mcgill — matched by CVE ID, not by vendor name.