Opensis
Vendor:
First CVE: Dec 9, 2013 · Active for 12 years
81
Total CVEs
More Total CVEs than 99% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
8.6
Avg CVSS
Higher Avg CVSS than 77% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Opensis over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 9, 2013
12 years ago
Most Recent CVE
Jul 14, 2026
12 days ago
CVE Severity & Scoring
Opensis81 CVEs
14%
48%
38%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network79 (97.5%)
Unknown2 (2.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low78 (96.3%)
High1 (1.2%)
Unknown2 (2.5%)
User Interaction
None70 (86.4%)
Unknown2 (2.5%)
Required9 (11.1%)
Privileges Required
Low30 (37.0%)
High0 (0.0%)
None49 (60.5%)
Unknown2 (2.5%)
Top CVEs
Signals from CVEs in this product scope (81 CVEs).
81 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13381CRITICAL openSIS through 7.4 allows SQL Injection. | Jul 1, 2020 | 9.8 | 73 | NO | YES |
CVE-2020-13383HIGH openSIS through 7.4 allows Directory Traversal. | Jul 1, 2020 | 7.5 | 66 | NO | YES |
CVE-2020-13382CRITICAL openSIS through 7.4 has Incorrect Access Control. | Jul 1, 2020 | 9.1 | 62 | NO | YES |
CVE-2013-1349HIGH Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter. | Dec 9, 2013 | 7.5 | 54 | NO | YES |
CVE-2020-6637CRITICAL openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php. | Aug 24, 2020 | 9.8 | 51 | NO | YES |
CVE-2021-40651MEDIUM OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem | Sep 29, 2021 | 6.5 | 49 | NO | YES |
CVE-2021-40617CRITICAL An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php. | Oct 11, 2021 | 9.8 | 44 | NO | YES |
CVE-2021-41691CRITICAL A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /Transfer | Jun 24, 2025 | 9.8 | 42 | NO | YES |
CVE-2021-39378CRITICAL A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaD | Sep 1, 2021 | 9.8 | 42 | NO | NO |
CVE-2024-51211CRITICAL SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $u | Nov 8, 2024 | 9.8 | 39 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (81 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
4.9% of CVEs· 97th percentile
Nuclei
7 CVEs
8.6% of CVEs· 97th percentile
ExploitDB
4 CVEs
4.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (81 CVEs).
Media Mentions
Signals from CVEs in this product scope (81 CVEs).
Top CNAs Publishing CVEs For Opensis
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.3 | 1 | 6.5 | 0.4% | 0 | 0 |
| 9.1 | 4 | 8.9 | 2.4% | 0 | 3 |
| 9.0 | 8 | 7.7 | 1.3% | 0 | 2 |
| 8.0 | 20 | 8.6 | 4.0% | 0 | 5 |
| 7.4 | 2 | 9.8 | 6.2% | 0 | 0 |
| 7.3 | 27 | 9.1 | 2.7% | 0 | 1 |
| 5.3 | 1 | 7.5 | 2.1% | 0 | 0 |
| 5.2 | 1 | 7.5 | 23.3% | 0 | 1 |
| 5.1 | 1 | 7.5 | 23.3% | 0 | 1 |
| 5.0 | 1 | 7.5 | 23.3% | 0 | 1 |
| 4.9 | 1 | 7.5 | 23.3% | 0 | 1 |
| 4.8.1 | 1 | 7.5 | 23.3% | 0 | 1 |
| 4.8 | 1 | 7.5 | 23.3% | 0 | 1 |
| 4.7 | 1 | 7.5 | 23.3% | 0 | 1 |
| 4.6 | 1 | 7.5 | 23.3% | 0 | 1 |
| 4.5 | 2 | 7.5 | 12.7% | 0 | 1 |