PKP (Public Knowledge Project) maintains a modest but widely used suite of scholarly publishing and journal-management software, with Open Journal Systems serving as its primary deployed product across academic institutions globally. The vendor's vulnerability profile concentrates on web-application security issues endemic to systems handling user input and session state, with recurrent weaknesses including cross-site request forgery, path traversal, cross-site scripting, and insufficient session expiration; these classes are characteristic of platforms managing editorial workflows and user authentication across distributed deployments. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pkp over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1467MEDIUM Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, allow remote authenticated users to (1) delete or (2) ren | Sep 6, 2012 | 6.5 | 32 | NO | YES |
CVE-2012-1468MEDIUM Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute arbitrary code by uploading a f | Sep 6, 2012 | 6.0 | 31 | NO | YES |
CVE-2012-1469MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remote authenticated users to inject arbitrary web script or HTM | Sep 6, 2012 | 4.3 | 25 | NO | YES |
CVE-2023-5899HIGH Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | Nov 1, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-5898HIGH Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | Nov 1, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-5889HIGH Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | Nov 1, 2023 | 8.2 | 23 | NO | NO |
CVE-2023-4695HIGH Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | Sep 1, 2023 | 8.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pkp.
Media articles that mention a CVE ID that affects a product developed by Pkp — matched by CVE ID, not by vendor name.