Schoolbox is an education-sector learning management and student information platform that maintains a focused but notably prominent footprint for its vertical. Its vulnerability disclosures cluster around application-layer input-handling weaknesses, principally cross-site scripting and SQL injection, which are characteristic of web-facing education platforms processing student and institutional data. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Schoolbox over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-28094HIGH Chat functionality in Schoolbox application before
version 23.1.3 is vulnerable to blind SQL Injection enabling the
authenticated attackers to read, modify, and delete database r | Mar 7, 2024 | 8.8 | 26 | NO | NO |
CVE-2022-3059HIGH
The application was vulnerable to multiple instances of SQL injection (authenticated and unauthenticated) through a vulnerable parameter. Due to the stacked query support, complex | Oct 31, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-39020MEDIUM
Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calen | Oct 31, 2022 | 6.1 | 22 | NO | NO |
CVE-2024-28097MEDIUM Calendar functionality in Schoolbox application
before version 23.1.3 is vulnerable to stored cross-site scripting
allowing authenticated attacker to perform security actions in | Mar 7, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-28096MEDIUM Class functionality in Schoolbox application
before version 23.1.3 is vulnerable to stored cross-site scripting
allowing authenticated attacker to perform security actions in the | Mar 7, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-28095MEDIUM News functionality in Schoolbox application before
version 23.1.3 is vulnerable to stored cross-site scripting allowing
authenticated attacker to perform security actions in the | Mar 7, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Schoolbox.
Media articles that mention a CVE ID that affects a product developed by Schoolbox — matched by CVE ID, not by vendor name.