All 2 CVE vulnerabilities found in Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning, with AI-generated Chinese analysis, references, and POCs.
Vendor: kodezen
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-104022 | Academy LMS <= 4.0.3 - Authenticated (Custom+) Privilege Escalation to add_child REST endpoint CWE-269 | 5.4 | Medium | 2026-10-10 |
| CVE-2026-104915 | Academy LMS <= 4.0.3 - Missing Authorization to Authenticated (Custom+) Arbitrary Academy Comment Deletion via delete_lesson_comment AJAX — Attacker-Controlled course_id vs. Target comment_id CWE-862 | 6.5 | Medium | 2026-10-10 |
All 2 known CVE vulnerabilities affecting Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning with full Chinese analysis, references, and POCs where available.