Polarlearn's vulnerability profile centers on its single learning platform product, which presents a modestly represented but structurally important education software target. The recurring weakness classes—improper authorization, cross-site request forgery, sensitive information exposure, improper authentication, and input-validation issues—are characteristic of web-facing applications where access control and session management form the core attack surface. Defenders should prioritize patching this vendor's releases given its direct role in user data handling and institutional access; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Polarlearn over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39322HIGH PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates a valid session for banned accounts before verifying the su | Apr 7, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-35610HIGH PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, password) and deleteUser(userId) in the account-management module | Apr 7, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-25221HIGH PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, the OAuth 2.0 implementation for GitHub and Google login providers is vulnerable to Login Cro | Feb 2, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-25885HIGH PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss://polarlearn.nl/api/v1/ws can be used without logging in. An | Feb 9, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-25126HIGH PolarLearn is a free and open-source learning program. Prior to version 0-PRERELEASE-15, the vote API route (`POST /api/v1/forum/vote`) trusts the JSON body’s `direction` value wit | Jan 29, 2026 | 7.1 | 24 | NO | NO |
CVE-2026-25222HIGH PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, a timing attack vulnerability in the sign-in process allows unauthenticated attackers to dete | Feb 2, 2026 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Polarlearn.
Media articles that mention a CVE ID that affects a product developed by Polarlearn — matched by CVE ID, not by vendor name.