Ankitects maintains Anki, a widely used open-source spaced-repetition learning application whose vulnerability profile centers on web-related input-handling issues such as cross-site scripting, script-injection flaws, and incomplete input sanitization. The exposure reflects the application's integration of web technologies and third-party functionality within a desktop and mobile learning platform. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ankitects over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-32484HIGH An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execut | Jul 22, 2024 | 8.2 | 37 | NO | NO |
CVE-2025-62186HIGH Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio because of URL scheme mishandling. | Oct 7, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-62185HIGH In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed for a YouTube link in the deck. The exec | Oct 7, 2025 | 7.8 | 25 | NO | NO |
CVE-2024-32152MEDIUM A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixe | Jul 22, 2024 | 4.3 | 19 | NO | NO |
CVE-2025-43703MEDIUM An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access to the internal API (even though the attacker has no knowled | Apr 16, 2025 | 5.4 | 18 | NO | NO |
In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessaril | Oct 7, 2025 | 3.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ankitects.
Media articles that mention a CVE ID that affects a product developed by Ankitects — matched by CVE ID, not by vendor name.