Lms
This hub aggregates every CVE we track for Lms, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
43
CVEs tracked
2
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM26LOW6HIGH3CRITICAL2
Monthly trend
0
1
0
1
0
0
0
0
1
1
1
1
7
2
3
2
2
0
2
1
5
2
0
1
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Lms.
- CVE-2026-54343Frappe LMS: Path Traversal in SCORM File Serving
- CVE-2026-39385Frappe LMS enrollment bypass in paid courses via unrelated batch
- CVE-2026-27404WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-40457Reflected XSS in LMS
- CVE-2026-40456OS Command Injection in LMS
- CVE-2026-40455SQL Injection in LMS
- CVE-2026-46546Frappe LMS: HTML injection in user-controlled metadata5.4
- CVE-2026-48559Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags5.4
- CVE-2026-39405Frappe has Path Transversal via SCORM
- CVE-2026-39415Frappe Learning Management System has Client-Side Manipulation of Quiz Scores4.3
- CVE-2026-34606Stored XSS in Frappe LMS6.1
- CVE-2026-26977Frappe Learning Management System exposes details of unpublished courses to unauthorized users5.3
- CVE-2026-26031Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students5.3
- CVE-2026-1106Chamilo LMS Legal Consent SocialController.php deleteLegal improper authorization5.4
- CVE-2026-23497Frappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs Pages5.4
Product normalization is registry-driven with AI assist and human review. How it works