Schoolcms is a learning management system whose vulnerability footprint concentrates in its core platform product and clusters around web application input-handling and file-upload controls, including cross-site scripting, SQL injection, unrestricted file uploads, and downstream injection issues. These recurrent weakness classes reflect the data-input and output-rendering demands typical of web-based educational platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Schoolcms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-4795HIGH A vulnerability classified as critical has been found in gongfuxiang schoolcms 2.3.1. This affects the function SaveInfo of the file /index.php?m=Admin&c=article&a=SaveInfo. The ma | May 16, 2025 | 7.2 | 20 | NO | NO |
CVE-2019-9572HIGH SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using the .zip extension along with the _Static substring, changing | Mar 5, 2019 | 7.2 | 19 | NO | NO |
CVE-2019-9181HIGH SchoolCMS version 2.3.1 allows file upload via the logo upload feature at admin.php?m=admin&c=site&a=save by using the .jpg extension, changing the Content-Type to image/php, and p | Feb 26, 2019 | 7.2 | 19 | NO | NO |
CVE-2019-8335MEDIUM An issue was discovered in SchoolCMS 2.3.1. There is an XSS vulnerability via index.php?a=Index&c=Channel&m=Home&id=[XSS]. | Feb 13, 2019 | 6.1 | 17 | NO | NO |
CVE-2019-8334MEDIUM An issue was discovered in SchoolCMS 2.3.1. There is an XSS vulnerability via index.php?a=Index&c=Channel&m=Home&viewid=[XSS]. | Feb 13, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Schoolcms.
Media articles that mention a CVE ID that affects a product developed by Schoolcms — matched by CVE ID, not by vendor name.