Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

LMS — Vulnerabilities & Security Advisories 42

All 42 CVE vulnerabilities found in LMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerability data for the Learning Management System (LMS), categorized by specific weakness types and vendor advisories. It collects a comprehensive history of security defects reported over the past five years, covering all major LMS platforms. Here, you can track vendor-issued security advisories, analyze the prevalence of specific weakness classes like SQL injection or access control flaws, and review the complete vulnerability timeline for a given product.

Vendor: Fernus Informatics

CVE ID Title CVSS Severity Published
CVE-2026-96777 Forma LMS Multi-User-Selector AJAX Endpoint getData getDataTask sql injection CWE-89 6.3 Medium 2026-09-24
CVE-2026-54343 Frappe LMS: Path Traversal in SCORM File Serving CWE-22 8.7 High 2026-09-17
CVE-2026-39385 Frappe LMS enrollment bypass in paid courses via unrelated batch CWE-288 - - 2026-07-20
CVE-2026-27404 WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-07-02
CVE-2026-40457 Reflected XSS in LMS CWE-79 - - 2026-06-18
CVE-2026-40456 OS Command Injection in LMS CWE-78 - - 2026-06-18
CVE-2026-40455 SQL Injection in LMS CWE-89 - - 2026-06-18
CVE-2026-46546 Frappe LMS: HTML injection in user-controlled metadata CWE-74 - - 2026-06-09
CVE-2026-48559 Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags CWE-79 5.4 Medium 2026-06-01
CVE-2026-39405 Frappe has Path Transversal via SCORM CWE-22 - - 2026-05-20
CVE-2026-39415 Frappe Learning Management System has Client-Side Manipulation of Quiz Scores CWE-602 7.1AI High AI 2026-04-08
CVE-2026-34606 Stored XSS in Frappe LMS CWE-79 5.4AI Medium AI 2026-04-02
CVE-2026-26977 Frappe Learning Management System exposes details of unpublished courses to unauthorized users CWE-862 4.3 - 2026-02-20
CVE-2026-26031 Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students CWE-863 5.3AI Medium AI 2026-02-11
CVE-2026-1106 Chamilo LMS Legal Consent SocialController.php deleteLegal improper authorization CWE-285 5.4 Medium 2026-01-18
CVE-2026-23497 Frappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs Pages CWE-79 5.4AI Medium AI 2026-01-14
CVE-2025-67734 Frappe Authenticated Users can Execute JavaScript through its Job Form CWE-79 5.4AI Medium AI 2025-12-12
CVE-2025-67730 Frappe authenticated users can execute XSS through form description fields CWE-79 5.4AI Medium AI 2025-12-12
CVE-2025-66581 Frappe LMS is Missing Server-Side Authorization in Business Logic CWE-863 8.8 - 2025-12-05
CVE-2025-64707 Frappe LMS revoking access did not show immediate effect as roles were cached CWE-863 6.3 - 2025-11-12
CVE-2025-64705 Frappe user was able to access the submission of other students CWE-200 4.6 - 2025-11-12
CVE-2025-62779 Frappe Learning users were able to add HTML through input fields in the Job Form CWE-79 5.4AI Medium AI 2025-10-27
CVE-2025-62778 Frappe Learning allowed students to access the Quiz Form via direct URL CWE-425 5.3AI Medium AI 2025-10-27
CVE-2025-62158 Frappe had attachments made by students to their assignments of type Text set to public CWE-200 7.5AI High AI 2025-10-10
CVE-2025-11283 Frappe LMS Course cross site scripting CWE-79 2.4 Low 2025-10-05
CVE-2025-11282 Frappe LMS Incomplete Fix CVE-2025-55006 cross site scripting CWE-79 2.4 Low 2025-10-05
CVE-2025-11281 Frappe LMS Unpublished Course courses access control CWE-284 5.0 Medium 2025-10-05
CVE-2025-11280 Frappe LMS Assignment Picture files direct request CWE-425 3.7 Low 2025-10-05
CVE-2025-59415 Frappe Learning vulnerable to Malicious Content upload via Profile bio field CWE-79 4.6 Medium 2025-09-17
CVE-2025-55006 Frappe Learning Holds Potential for Malicious SVG Upload in Image Upload Feature CWE-20 4.3 Medium 2025-08-09

All 42 known CVE vulnerabilities affecting LMS with full Chinese analysis, references, and POCs where available.