SFU maintains a modestly represented portfolio of academic publishing and web application platforms, most notably the widely adopted Open Journal System and its associated PKP Web Application Library. The vendor's vulnerability exposure centers on application-layer input handling and request validation, with recurring weakness classes including cross-site scripting, cross-site request forgery, code injection, and deserialization flaws that are characteristic of web-facing PHP-based software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sfu over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19909HIGH An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report g | Dec 19, 2019 | 8.8 | 26 | NO | NO |
CVE-2023-5897HIGH Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1. | Nov 1, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-5893HIGH Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | Nov 1, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-5626HIGH Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16. | Oct 18, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-25436MEDIUM A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into th | Mar 1, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-5900MEDIUM Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
| Nov 7, 2023 | 4.3 | 18 | NO | NO |
CVE-2023-47271MEDIUM PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML docume | Nov 6, 2023 | 5.3 | 18 | NO | NO |
CVE-2023-5890MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | Nov 1, 2023 | 5.4 | 18 | NO | NO |
CVE-2018-12229MEDIUM Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 allows remote attackers to inject arbitrary web script or HTML | Jun 12, 2018 | 6.1 | 18 | NO | NO |
CVE-2023-5904MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | Nov 7, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sfu.
Media articles that mention a CVE ID that affects a product developed by Sfu — matched by CVE ID, not by vendor name.