Os4ed maintains a narrowly scoped but prominently positioned educational platform product, OpenSIS, that serves schools and districts across a wide deployment footprint. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the web-application architecture and the high-value nature of student records and administrative access. The exposure recurs through application-layer input-handling and authorization weaknesses including SQL injection, path traversal, cross-site scripting, code injection, and authorization-bypass flaws that are endemic to web platforms handling sensitive institutional data. Defenders should treat OpenSIS deployments as high-priority patching targets given the confluence of critical severity, public exploit availability, and the administrative reach of the platform in educational networks. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Os4ed over time
Signals from CVEs in this vendor scope (81 CVEs).
81 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13381CRITICAL openSIS through 7.4 allows SQL Injection. | Jul 1, 2020 | 9.8 | 73 | NO | YES |
CVE-2020-13383HIGH openSIS through 7.4 allows Directory Traversal. | Jul 1, 2020 | 7.5 | 66 | NO | YES |
CVE-2020-13382CRITICAL openSIS through 7.4 has Incorrect Access Control. | Jul 1, 2020 | 9.1 | 62 | NO | YES |
CVE-2013-1349HIGH Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter. | Dec 9, 2013 | 7.5 | 54 | NO | YES |
CVE-2020-6637CRITICAL openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php. | Aug 24, 2020 | 9.8 | 51 | NO | YES |
CVE-2021-40651MEDIUM OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem | Sep 29, 2021 | 6.5 | 49 | NO | YES |
CVE-2021-40617CRITICAL An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php. | Oct 11, 2021 | 9.8 | 44 | NO | YES |
CVE-2021-41691CRITICAL A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /Transfer | Jun 24, 2025 | 9.8 | 42 | NO | YES |
CVE-2021-39378CRITICAL A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaD | Sep 1, 2021 | 9.8 | 42 | NO | NO |
CVE-2024-51211CRITICAL SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $u | Nov 8, 2024 | 9.8 | 39 | NO | YES |
Signals from CVEs in this vendor scope (81 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Os4ed.
Media articles that mention a CVE ID that affects a product developed by Os4ed — matched by CVE ID, not by vendor name.