Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42857 |
|
Cross-Site Scripting (XSS) in django (CVE-2026-42857)
cross-site scripting in django (CVE-2026-42857). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42858 |
|
SSRF (Server-Side Request Forgery) in openedx (CVE-2026-42858)
SSRF in openedx (CVE-2026-42858). Confidential information can be exposed externally.
|
| CVE-2026-42860 |
|
SSRF (Server-Side Request Forgery) in edx-enterprise (CVE-2026-42860)
SSRF in edx-enterprise (CVE-2026-42860). Confidential information can be exposed externally. Exploitable via ``sync_provider_data``. Mitigation: upgrade to `7.0.5` or later.
|
| CVE-2026-35404 |
|
Open Redirect in openedx (CVE-2026-35404)
vulnerability in openedx (CVE-2026-35404). Risk of unauthorized operations or information disclosure.
|