Untis develops WebUntis, a web-based educational scheduling and timetabling platform deployed across schools and educational institutions, with its vulnerability exposure centered on web-application input handling. The recurring weakness classes affecting this product—cross-site request forgery and cross-site scripting—reflect the challenges of securing form-based web interfaces that handle student and staff data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Untis over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10540HIGH Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules. | Mar 13, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-22453MEDIUM Untis WebUntis before 2020.9.6 allows XSS in multiple functions that store information. | Sep 24, 2020 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Untis.
Media articles that mention a CVE ID that affects a product developed by Untis — matched by CVE ID, not by vendor name.