| CVE-2025-32141 | WordPress MasterStudy LMS plugin <= 3.5.28 - Local File Inclusion vulnerability | Stylemix | MasterStudy LMS | High | 8.8 | 2025-04-04 15:58:33 | Deep Dive |
| CVE-2025-22740 | WordPress Sensei LMS plugin <= 4.24.4 - Broken Access Control vulnerability | Automattic | Sensei LMS | Medium | 5.3 | 2025-03-27 21:20:59 | Deep Dive |
| CVE-2025-2290 | LifterLMS <= 8.0.1 - Missing Authorization to Unauthenticated Post Trashing | chrisbadgett | LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes | Medium | 5.3 | 2025-03-19 04:21:06 | Deep Dive |
| CVE-2025-27353 | WordPress Namaste! LMS Plugin <= 2.6.5 - Cross Site Request Forgery (CSRF) vulnerability | Bob | Namaste! LMS | Medium | 4.3 | 2025-02-24 14:49:25 | Deep Dive |
| CVE-2025-0466 | Sensei LMS < 4.24.4 - Unauthenticated sensei_email/sensei_message Disclosure | Unknown | Sensei LMS | 中危 | - | 2025-02-04 06:00:12 | Deep Dive |
| CVE-2025-24630 | WordPress Sikshya LMS Plugin <= 0.0.21 - Reflected Cross Site Scripting (XSS) vulnerability | MantraBrain | Sikshya LMS | High | 7.1 | 2025-02-03 14:22:48 | Deep Dive |
| CVE-2025-24662 | WordPress LearnDash LMS Plugin <= 4.20.0.1 - Broken Access Control vulnerability | LearnDash | LearnDash LMS | Medium | 5.3 | 2025-01-27 14:22:17 | Deep Dive |
| CVE-2024-13599 | LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 6.4 | 2025-01-25 07:24:16 | Deep Dive |
| CVE-2024-11328 | CLUEVO LMS, E-Learning Platform <= 1.13.2 - Reflected Cross-Site Scripting | cluevo | CLUEVO LMS, E-Learning Platform | Medium | 6.1 | 2025-01-09 11:10:59 | Deep Dive |
| CVE-2024-8002 | VIWIS LMS File Upload cross site scripting | VIWIS | LMS | Medium | 4.3 | 2025-01-08 06:50:29 | Deep Dive |
| CVE-2025-22334 | WordPress Education LMS theme <= 0.0.7 - Stored Cross Site Scripting (XSS) vulnerability | FilaThemes | Education LMS | Medium | 6.5 | 2025-01-07 16:54:20 | Deep Dive |
| CVE-2024-37093 | WordPress MasterStudy LMS plugin <= 3.2.1 - Cross Site Request Forgery (CSRF) vulnerability | Stylemix | MasterStudy LMS | Medium | 4.3 | 2025-01-02 12:00:40 | Deep Dive |
| CVE-2024-12596 | LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes <= 7.8.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion | chrisbadgett | LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes | Medium | 4.3 | 2024-12-18 03:22:06 | Deep Dive |
| CVE-2024-12127 | Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS <= 0.0.21 - Reflected Cross-Site Scripting via page Parameter | mantrabrain | Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS | Medium | 6.1 | 2024-12-17 09:22:42 | Deep Dive |
| CVE-2024-54296 | WordPress CoSchool LMS plugin <= 1.4.3 - Account Takeover vulnerability | Codexpert, Inc | CoSchool LMS | Critical | 9.8 | 2024-12-13 14:25:09 | Deep Dive |
| CVE-2024-12172 | WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Update | hookandhook | WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses | High | 7.5 | 2024-12-12 05:24:22 | Deep Dive |
| CVE-2024-11868 | LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 5.3 | 2024-12-10 12:25:00 | Deep Dive |
| CVE-2024-53816 | WordPress Tutor LMS Elementor Addons plugin <= 2.1.5 - Broken Access Control vulnerability | Themeum | Tutor LMS Elementor Addons | Medium | 4.3 | 2024-12-09 12:59:40 | Deep Dive |
| CVE-2024-53791 | WordPress Lenxel Core plugin <= 1.2.8 - Cross Site Scripting (XSS) vulnerability | Ogun Labs | Lenxel Core for Lenxel(LNX) LMS | Medium | 6.5 | 2024-12-09 12:57:18 | Deep Dive |
| CVE-2024-53790 | WordPress Lenxel Core plugin <= 1.2.8 - Local File Inclusion vulnerability | Ogun Labs | Lenxel Core for Lenxel(LNX) LMS | High | 7.5 | 2024-12-09 12:22:30 | Deep Dive |