Lms
This hub aggregates every CVE we track for Lms, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
37
CVEs tracked
2
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM26LOW6HIGH3CRITICAL2
Monthly trend
1
0
1
0
1
0
0
0
0
1
1
1
1
7
2
3
2
2
0
2
0
2
1
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Lms.
- CVE-2026-27404WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-46546Frappe LMS: HTML injection in user-controlled metadata5.4
- CVE-2026-48559Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags5.4
- CVE-2026-39415Frappe Learning Management System has Client-Side Manipulation of Quiz Scores4.3
- CVE-2026-34606Stored XSS in Frappe LMS6.1
- CVE-2026-26977Frappe Learning Management System exposes details of unpublished courses to unauthorized users5.3
- CVE-2026-26031Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students5.3
- CVE-2026-1106Chamilo LMS Legal Consent SocialController.php deleteLegal improper authorization5.4
- CVE-2026-23497Frappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs Pages5.4
- CVE-2025-67734Frappe Authenticated Users can Execute JavaScript through its Job Form5.4
- CVE-2025-67730Frappe authenticated users can execute XSS through form description fields5.4
- CVE-2025-66581Frappe LMS is Missing Server-Side Authorization in Business Logic6.5
- CVE-2025-64707Frappe LMS revoking access did not show immediate effect as roles were cached5.4
- CVE-2025-64705Frappe user was able to access the submission of other students4.3
- CVE-2025-62779Frappe Learning users were able to add HTML through input fields in the Job Form5.4
Product normalization is registry-driven with AI assist and human review. How it works