VYPR

Oppia

by Oppia

CVEs (3)

  • CVE-2026-85210MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific…

  • CVE-2023-40021MedAug 16, 2023
    risk 0.00cvss 5.3epss 0.01

    Oppia is an online learning platform. When comparing a received CSRF token against the expected token, Oppia uses the string equality operator (`==`), which is not safe against timing attacks. By repeatedly submitting invalid tokens, an attacker can brute-force the expected CSRF…

  • CVE-2021-41733MedNov 8, 2021
    risk 0.00cvss 6.1epss 0.01

    Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.