Vendor
Oppia
Products
1
CVEs
3
Across products
3
Status
Private
Products
1- 3 CVEs
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-41733 | Med | 0.40 | 6.1 | 0.01 | Nov 8, 2021 | Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them. | ||
| CVE-2026-85210 | Med | 0.28 | 4.3 | 0.00 | Sep 3, 2026 | Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific… | ||
| CVE-2023-40021 | Med | 0.00 | 5.3 | 0.01 | Aug 16, 2023 | Oppia is an online learning platform. When comparing a received CSRF token against the expected token, Oppia uses the string equality operator (`==`), which is not safe against timing attacks. By repeatedly submitting invalid tokens, an attacker can brute-force the expected CSRF… |
- risk 0.40cvss 6.1epss 0.01
Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.
- risk 0.28cvss 4.3epss 0.00
Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific…
- risk 0.00cvss 5.3epss 0.01
Oppia is an online learning platform. When comparing a received CSRF token against the expected token, Oppia uses the string equality operator (`==`), which is not safe against timing attacks. By repeatedly submitting invalid tokens, an attacker can brute-force the expected CSRF…