Oppia is an open-source learning platform focused on interactive educational content delivery, with its vulnerability footprint centered on a single product line. The recurring weaknesses—observable timing and state discrepancies, and open-redirect flaws—reflect the authentication, session-state, and navigation logic typical of web-based educational applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oppia over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41733MEDIUM Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them. | Nov 8, 2021 | 6.1 | 22 | NO | NO |
CVE-2023-40021MEDIUM Oppia is an online learning platform. When comparing a received CSRF token against the expected token, Oppia uses the string equality operator (`==`), which is not safe against tim | Aug 16, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oppia.
Media articles that mention a CVE ID that affects a product developed by Oppia — matched by CVE ID, not by vendor name.