Melissa Guillermo, Eduardo Yu II, Dr. Reagan Ricafort
This study examined publicly disclosed Common Vulnerabilities and Exposures (CVE) records for Moodle, Chamilo, Canvas LMS, Open edX, and Sakai to assess their value for higher education security governance. A non-intrusive secondary-data audit analyzed 236 CVEs from 2018 to 3 June 2026 using platform, National Vulnerability Database (NVD) Published Date year, revised CVSS severity categories, and OWASP Top 10:2021 classifications. Six zero-score records were separated from low severity. A sensitivity analysis compared the full corpus with 211 NVD API-verified records. A blinded independent IT-faculty coder recoded 24 records; severity agreement was 100.0% (Cohen's kappa = 1.000), and OWASP agreement was 91.7% (Cohen's kappa = 0.814). Moodle and Chamilo represented 91.5% of the corpus, a disclosure-weighted pattern rather than a product ranking. A03 Injection (54.2%) and A01 Broken Access Control (31.4%) dominated. Among records with numeric CVSS scores, including six zero-score records, high/critical proportions were 45.3% (67/148) in the full corpus and 44.9% (66/147) in the NVD-verified subset. Canvas and Sakai findings were interpreted cautiously because of small denominators. Public CVE evidence is affected by disclosure asymmetry, incomplete CVSS metadata, NVD non-returned records, and deployment differences. Because identifiable CVSS version/vector metadata were not preserved, severity comparisons are descriptive rather than version-normalized. The audit offers a reproducible governance framework linking vulnerability patterns to patching, authorization review, content-ingestion controls, plugin governance, and supplier accountability without treating raw CVE counts as inherent security rankings.