AnkiWeb is a cloud synchronization and study platform for the Anki flashcard application, occupying a niche role in the learning-software ecosystem. The durable signal across its disclosures centers on application-layer injection and unsafe handling of untrusted dependencies, reflecting the integration demands of a web-facing sync service that bridges client and cloud storage. Current severity, exploitation, and exposure counts are shown in the live statistics panel alongside this summary.
The number and severity of CVEs published that impact products developed by Ankiweb over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-26020HIGH An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attack | Jul 22, 2024 | 8.8 | 33 | NO | NO |
CVE-2024-29073MEDIUM An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by default | Jul 22, 2024 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ankiweb.
Media articles that mention a CVE ID that affects a product developed by Ankiweb — matched by CVE ID, not by vendor name.