openedx-platform vulnerabilities
CVEs whose affected-version data names the openedx-platform package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-85272Medium· 4.3PoCOpen edX Platform enables the authoring and delivery of online learning at any scale
Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate safe_extractall targets by comparing resolved…
▾ Twilightopenedx · openedx-platformEPSS 0.33%via NVD
CVE-2026-85271Medium· 6.1Open edX Platform enables the authoring and delivery of online learning at any scale
Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawood.1, the add_additional_attributes_to_notifications function in openedx/core/djangoapps/notifications/email/utils.py…
▾ Sunlitopenedx · openedx-platformEPSS 0.20%via NVD