This page aggregates publicly disclosed CVE and security risk information related to irohasoft, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-48497 | Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a specially crafted URL while being logged in to the affected product, arbitrary learning histories may be registered. | [email protected] | 5.1 | 0.09% | 2025-06-26 | 2025-09-30 |
| CVE-2025-41404 | Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is exploited, non-public contents may be viewed by an attacker who can log in to the affected product. | [email protected] | 5.3 | 0.14% | 2025-06-26 | 2025-09-30 |