CVE-2025-32808: Wwnorton Inquizitive
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into the backend, because only client-side access control exists.
Affected products
- Wwnorton Inquizitive: up to and including 2025-04-08
Published 2025-04-11. Last modified 2026-06-17.