VendorsFrappelearningall versions
Vulnerabilities

Frappe Learning (LMS)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2023-42807
Frappe LMS SQL Injection Issue on People Page
Published 2023-09-21 · Modified
9.8EPSS 0.004
CVE-2025-55006
Frappe Learning Holds Potential for Malicious SVG Upload in Image Upload Feature
Published 2025-08-09 · Analyzed
8.8EPSS 0.003
CVE-2023-5555
Cross-site Scripting (XSS) - Generic in frappe/lms
Published 2023-10-12 · Modified
7.1EPSS 0.004
CVE-2026-34606
Stored XSS in Frappe LMS
Published 2026-04-02 · Analyzed
6.9EPSS 0.003
CVE-2026-26977
Frappe Learning Management System exposes details of unpublished courses to unauthorized users
Published 2026-02-20 · Analyzed
6.9EPSS 0.003
CVE-2025-66581
Frappe LMS is Missing Server-Side Authorization in Business Logic
Published 2025-12-05 · Analyzed
6.5EPSS 0.002
CVE-2025-11282
Frappe LMS Incomplete Fix CVE-2025-55006 cross site scripting
Published 2025-10-05 · Modified
6.1EPSS 0.004
CVE-2025-59415
Frappe Learning vulnerable to Malicious Content upload via Profile bio field
Published 2025-09-17 · Analyzed
5.4EPSS 0.002
CVE-2026-46546
Frappe LMS: HTML injection in user-controlled metadata
Published 2026-06-09 · Analyzed
5.4EPSS 0.002
CVE-2025-62779
Frappe Learning users were able to add HTML through input fields in the Job Form
Published 2025-10-27 · Analyzed
5.4EPSS 0.002
CVE-2025-67730
Frappe authenticated users can execute XSS through form description fields
Published 2025-12-12 · Analyzed
5.4EPSS 0.002
CVE-2025-67734
Frappe Authenticated Users can Execute JavaScript through its Job Form
Published 2025-12-12 · Analyzed
5.4EPSS 0.002
CVE-2026-23497
Frappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs Pages
Published 2026-01-14 · Analyzed
5.4EPSS 0.002
CVE-2025-64707
Frappe LMS revoking access did not show immediate effect as roles were cached
Published 2025-11-12 · Analyzed
5.4EPSS 0.002
CVE-2026-26031
Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students
Published 2026-02-11 · Analyzed
5.3EPSS 0.003
CVE-2025-62158
Frappe had attachments made by students to their assignments of type Text set to public
Published 2025-10-10 · Analyzed
5.3EPSS 0.003
CVE-2026-39415
Frappe Learning Management System has Client-Side Manipulation of Quiz Scores
Published 2026-04-08 · Analyzed
5.3EPSS 0.003
CVE-2025-62778
Frappe Learning allowed students to access the Quiz Form via direct URL
Published 2025-10-27 · Analyzed
5.3EPSS 0.002
CVE-2025-11281
Frappe LMS Unpublished Course courses access control
Published 2025-10-05 · Analyzed
5.0EPSS 0.004
CVE-2025-64705
Frappe user was able to access the submission of other students
Published 2025-11-12 · Analyzed
4.3EPSS 0.002
CVE-2025-11280
Frappe LMS Assignment Picture files direct request
Published 2025-10-05 · Analyzed
3.7EPSS 0.005
CVE-2025-11283
Frappe LMS Course cross site scripting
Published 2025-10-05 · Analyzed
3.3EPSS 0.004