classroomio CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

classroomio vulnerability overview

Aggregates CVE and security vulnerability intelligence across all classroomio-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting; exposure may include vendor impact session compromise in vendor surface software deployment and vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-67298 An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile [email protected] 8.1 0.22% 2026-03-11 2026-04-07
CVE-2025-65670 An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized disclosure of sensitive course, admin, and student data. The leak occurs momentarily before the system reverts to a normal state restricting access. [email protected] 4.3 0.24% 2025-11-26 2025-12-03
CVE-2025-65676 Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images. [email protected] 5.4 0.23% 2025-11-26 2025-12-03
CVE-2025-65675 Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG profile pictures. [email protected] 5.4 0.23% 2025-11-26 2025-12-05
CVE-2025-65672 Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings. [email protected] 7.5 0.33% 2025-11-26 2025-12-05
CVE-2025-65669 An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing the expected admin-only deletion restriction. [email protected] 9.1 0.49% 2025-11-26 2025-12-03
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence