CVE-2025-32808: Wwnorton Inquizitive

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into the backend, because only client-side access control exists.

Affected products

  • Wwnorton Inquizitive: up to and including 2025-04-08

Published 2025-04-11. Last modified 2026-06-17.