Sunbird maintains a narrowly scoped web portal product that serves a focused user base, with its vulnerability footprint concentrated in application-layer web security issues. The recurring weakness classes—including cross-site request forgery, cross-site scripting, path traversal, improper certificate validation, and inefficient regular expression handling—reflect the input-handling and request-validation demands typical of portal applications. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sunbird over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-70031HIGH An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | Mar 9, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-70030HIGH An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | Mar 9, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-70027HIGH An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This allows attackers to obtain sensitive information | Mar 11, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-70028HIGH An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | Mar 9, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-70032MEDIUM An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | Mar 9, 2026 | 6.1 | 22 | NO | NO |
CVE-2025-70029HIGH An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disables TLS/SSL certificate validation by setting 'rejectUnauthor | Feb 11, 2026 | 7.5 | 22 | NO | NO |
CVE-2025-70033MEDIUM An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | Mar 9, 2026 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sunbird.
Media articles that mention a CVE ID that affects a product developed by Sunbird — matched by CVE ID, not by vendor name.