VendorsSunbirdsunbirded-portalall versions
Vulnerabilities

Sunbird Sunbirded-portal

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2025-70031
An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
Published 2026-03-09 · Analyzed
8.8EPSS 0.002
CVE-2025-70028
An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
Published 2026-03-09 · Analyzed
7.5EPSS 0.004
CVE-2025-70030
An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
Published 2026-03-09 · Modified
7.5EPSS 0.003
CVE-2025-70029
An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTP request options
Published 2026-02-11 · Analyzed
7.5EPSS 0.003
CVE-2025-70027
An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This allows attackers to obtain sensitive information
Published 2026-03-11 · Analyzed
7.5EPSS 0.003
CVE-2025-70032
An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
Published 2026-03-09 · Analyzed
6.1EPSS 0.002
CVE-2025-70033
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
Published 2026-03-09 · Analyzed
5.4EPSS 0.002