VendorsFrappelearningany version
Vulnerabilities

Frappe Learning (LMS) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2023-42807
Frappe LMS SQL Injection Issue on People Page
Published 2023-09-21 · Modified
9.8EPSS 0.004
CVE-2025-55006
Frappe Learning Holds Potential for Malicious SVG Upload in Image Upload Feature
Published 2025-08-09 · Analyzed
8.8EPSS 0.003
CVE-2026-34606
Stored XSS in Frappe LMS
Published 2026-04-02 · Analyzed
6.9EPSS 0.003
CVE-2026-26977
Frappe Learning Management System exposes details of unpublished courses to unauthorized users
Published 2026-02-20 · Analyzed
6.9EPSS 0.003
CVE-2025-66581
Frappe LMS is Missing Server-Side Authorization in Business Logic
Published 2025-12-05 · Analyzed
6.5EPSS 0.002
CVE-2025-11282
Frappe LMS Incomplete Fix CVE-2025-55006 cross site scripting
Published 2025-10-05 · Modified
6.1EPSS 0.004
CVE-2025-59415
Frappe Learning vulnerable to Malicious Content upload via Profile bio field
Published 2025-09-17 · Analyzed
5.4EPSS 0.002
CVE-2026-46546
Frappe LMS: HTML injection in user-controlled metadata
Published 2026-06-09 · Analyzed
5.4EPSS 0.002
CVE-2025-62779
Frappe Learning users were able to add HTML through input fields in the Job Form
Published 2025-10-27 · Analyzed
5.4EPSS 0.002
CVE-2025-67730
Frappe authenticated users can execute XSS through form description fields
Published 2025-12-12 · Analyzed
5.4EPSS 0.002
CVE-2025-67734
Frappe Authenticated Users can Execute JavaScript through its Job Form
Published 2025-12-12 · Analyzed
5.4EPSS 0.002
CVE-2025-64707
Frappe LMS revoking access did not show immediate effect as roles were cached
Published 2025-11-12 · Analyzed
5.4EPSS 0.002
CVE-2026-23497
Frappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs Pages
Published 2026-01-14 · Analyzed
5.4EPSS 0.002
CVE-2026-26031
Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students
Published 2026-02-11 · Analyzed
5.3EPSS 0.003
CVE-2026-39415
Frappe Learning Management System has Client-Side Manipulation of Quiz Scores
Published 2026-04-08 · Analyzed
5.3EPSS 0.003
CVE-2025-62778
Frappe Learning allowed students to access the Quiz Form via direct URL
Published 2025-10-27 · Analyzed
5.3EPSS 0.002
CVE-2025-64705
Frappe user was able to access the submission of other students
Published 2025-11-12 · Analyzed
4.3EPSS 0.002