OS4ED has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 6.3 (medium). The dominant weakness classes are CWE-74 (4) and CWE-89 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-103116Medium· 6.3OS4ED openSIS-Classic Student List Search Endpoint GetStuListFnc.php DBQuery sql injection35CVE-2026-103115Medium· 6.3OS4ED openSIS-Classic Student Search CustomFieldsFnc.php sql injection35CVE-2026-103114Medium· 6.3A vulnerability was identified in OS4ED openSIS-Classic up to 9.335CVE-2026-103113Medium· 4.7A vulnerability was determined in OS4ED openSIS-Classic up to 9.326
OS4ED vulnerabilities
CVEs affecting OS4ED, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-103115Medium· 6.3OS4ED openSIS-Classic Student Search CustomFieldsFnc.php sql injection
A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql inje…
CVE-2026-103116Medium· 6.3OS4ED openSIS-Classic Student List Search Endpoint GetStuListFnc.php DBQuery sql injection
A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes …
CVE-2026-103114Medium· 6.3A vulnerability was identified in OS4ED openSIS-Classic up to 9.3
A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment Management Endpoint. The manipulation of th…
CVE-2026-103113Medium· 4.7A vulnerability was determined in OS4ED openSIS-Classic up to 9.3
A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argume…