OpenEdx is an open-source learning management platform deployed across educational institutions and corporate training environments, with its vulnerability exposure centering on the core platform and extensible components such as XBlocks. The durable signal is a concentration of web-layer input-handling and authorization weaknesses—cross-site scripting, server-side request forgery, injection flaws, and missing authorization controls—that are characteristic of application platforms accepting user-generated content and integrating third-party tools. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openedx over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42858CRITICAL Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Adm | May 11, 2026 | 9.9 | 36 | NO | NO |
CVE-2026-42860HIGH The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync_provider_data endpoint in SAMLProviderDataViewSet fetches S | May 11, 2026 | 8.5 | 32 | NO | NO |
CVE-2024-43782CRITICAL This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pulling translations from the openedx | Aug 23, 2024 | 9.8 | 24 | NO | NO |
CVE-2026-42857MEDIUM Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to r | May 11, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-35404MEDIUM Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a redirect_url GET parameter that is passed directly to HttpR | Apr 6, 2026 | 6.1 | 23 | NO | NO |
CVE-2022-46147MEDIUM Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site | Nov 28, 2022 | 6.1 | 22 | NO | NO |
CVE-2023-23611MEDIUM LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provider tools. Versions 7.0.0 and above, prior to 7.2.2, are vuln | Jan 26, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openedx.
Media articles that mention a CVE ID that affects a product developed by Openedx — matched by CVE ID, not by vendor name.