All 40 CVE vulnerabilities found in LMS, with AI-generated Chinese analysis, references, and POCs.
This page documents common software vulnerabilities associated with Learning Management Systems, focusing on weakness types such as insecure direct object references, cross-site scripting, and improper access control within educational technology platforms. It aggregates a comprehensive collection of publicly disclosed security issues, covering advisory data from 2010 through 2023 to provide a historical perspective on the evolving threat landscape in this sector. By reviewing this curated information, users can effectively track vendor security advisories for specific LMS providers, gain a deeper understanding of prevalent weakness classes affecting educational software, and investigate the detailed vulnerability history of particular products to assess their current risk posture. The content is organized to facilitate rapid identification of critical flaws and to support security teams in prioritizing remediation efforts based on severity and exploitation potential. This resource serves as a centralized reference point for administrators and developers seeking to mitigate risks inherent in managing online learning environments, ensuring that security decisions are informed by accurate, up-to-date intelligence regarding known defects in widely used learning management platforms.
Vendor: Fernus Informatics
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-8002 | VIWIS LMS File Upload cross site scripting CWE-79 | 4.3 | Medium | 2025-01-08 |
| CVE-2024-8001 | VIWIS LMS Print authorization CWE-862 | 5.3 | Medium | 2024-11-13 |
| CVE-2024-3932 | Totara LMS User Selector cross-site request forgery CWE-352 | 3.1 | Low | 2024-04-18 |
| CVE-2024-3931 | Totara LMS User Selector check.php cross site scripting CWE-79 | 3.5 | Low | 2024-04-18 |
| CVE-2024-1439 | Inadequate access control vulnerability in Moodle CWE-284 | 6.5 | Medium | 2024-02-12 |
| CVE-2023-42807 | Frappe LMS SQL Injection Issue on People Page CWE-89 | 6.3 | Medium | 2023-09-21 |
| CVE-2023-4974 | Academy LMS GET Parameter filter sql injection CWE-89 | 6.3 | Medium | 2023-09-15 |
| CVE-2023-4973 | Academy LMS GET Parameter filter cross site scripting CWE-79 | 3.5 | Low | 2023-09-15 |
| CVE-2023-4119 | Academy LMS courses cross site scripting CWE-79 | 4.3 | Medium | 2023-08-03 |
| CVE-2023-1728 | Unrestricted Upload of File with Dangerous Type in Fernus LMS CWE-434 | 9.8 | Critical | 2023-04-04 |
All 40 known CVE vulnerabilities affecting LMS with full Chinese analysis, references, and POCs where available.