Classroomio is an education-focused web application platform whose vulnerability profile concentrates in a single product and skews toward serious outcomes, with a meaningful share reaching critical severity. The recurring exposure reflects characteristic weaknesses of web-based learning systems: authorization and authentication bypass flaws, cross-site scripting issues, and insufficient data-authenticity verification that can undermine access controls and user isolation in collaborative learning environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Classroomio over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65669CRITICAL An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing the e | Nov 26, 2025 | 9.1 | 31 | NO | NO |
CVE-2025-67298HIGH An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile | Mar 11, 2026 | 8.1 | 27 | NO | NO |
CVE-2025-65672HIGH Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings. | Nov 26, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-65675MEDIUM Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG profile pictures. | Nov 26, 2025 | 5.4 | 22 | NO | NO |
CVE-2025-65670MEDIUM An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauth | Nov 26, 2025 | 4.3 | 20 | NO | NO |
CVE-2025-65676MEDIUM Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images. | Nov 26, 2025 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Classroomio.
Media articles that mention a CVE ID that affects a product developed by Classroomio — matched by CVE ID, not by vendor name.