Skip to main content

Vendor/product archive

ilias / ilias CVEs

Beta · best-effort

42 CVEs tagged to ilias / ilias2 Critical, 9 High, 30 Medium, 1 Low, 0 Unrated.

CVE-2020-36944

Published Jan 28, 2026

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Att…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11346

Published Oct 6, 2025

A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_s…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2025-11345

Published Oct 6, 2025

A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It…

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2025-11344

Published Oct 6, 2025

A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate Import Handler. The manipulatio…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2024-33529

Published May 21, 2024

ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execute operating system commands via file…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-33528

Published May 21, 2024

A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary we…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33527

Published May 21, 2024

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticate…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33526

Published May 21, 2024

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenti…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36486

Published Dec 25, 2023

The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by u…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36485

Published Dec 25, 2023

The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user via…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45869

Published Oct 26, 2023

ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The inject…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45868

Published Oct 26, 2023

The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high-impact Directory Traversal attack on confidentiality and a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45867

Published Oct 26, 2023

ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker with a privileged account, typ…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36484

Published Jun 29, 2023

ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36488

Published Jun 29, 2023

ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36487

Published Jun 29, 2023

The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-45918

Published Dec 7, 2022

ILIAS before 7.16 allows External Control of File Name or Path.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31266

Published Jun 29, 2022

In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-23996

Published May 13, 2021

A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-23995

Published May 13, 2021

An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25268

Published Nov 10, 2020

Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25267

Published Nov 10, 2020

An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 42 CVEsPage 1 of 2