Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openedx

First CVE: Nov 28, 2022Active for: 4 yearsTotal CVEs: 7

OpenEdx is an open-source learning management platform deployed across educational institutions and corporate training environments, with its vulnerability exposure centering on the core platform and extensible components such as XBlocks. The durable signal is a concentration of web-layer input-handling and authorization weaknesses—cross-site scripting, server-side request forgery, injection flaws, and missing authorization controls—that are characteristic of application platforms accepting user-generated content and integrating third-party tools. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openedx over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 28, 2022
3 years ago
Most Recent CVE
May 11, 2026
74 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-42858CRITICAL
Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Adm
May 11, 20269.936NONO
CVE-2026-42860HIGH
The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync_provider_data endpoint in SAMLProviderDataViewSet fetches S
May 11, 20268.532NONO
CVE-2024-43782CRITICAL
This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pulling translations from the openedx
Aug 23, 20249.824NONO
CVE-2026-42857MEDIUM
Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to r
May 11, 20265.423NONO
CVE-2026-35404MEDIUM
Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a redirect_url GET parameter that is passed directly to HttpR
Apr 6, 20266.123NONO
CVE-2022-46147MEDIUM
Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site
Nov 28, 20226.122NONO
CVE-2023-23611MEDIUM
LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provider tools. Versions 7.0.0 and above, prior to 7.2.2, are vuln
Jan 26, 20235.419NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
57%
14%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (57.1%)
Unknown0 (0.0%)
Required3 (42.9%)
Privileges Required
Low4 (57.1%)
High0 (0.0%)
None3 (42.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openedx.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openedx — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openedx's Products

View all 1 CNAs →

Top CWEs