CVE-2025-40650: Clickedu

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Insecure Direct Object Reference (IDOR) vulnerability in Clickedu. This vulnerability could allow an attacker to retrieve information about student report cards.

Affected products

Published 2025-05-26. Last modified 2026-06-17.