Learning management system
This hub aggregates every CVE we track for Learning management system, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
12
CVEs tracked
2
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM7HIGH3CRITICAL2
Monthly trend
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
2024-102026-09
Latest CVEs
The 12 most recently published vulnerabilities affecting Learning management system.
- CVE-2026-12789ILIAS Learning Management System Learning Progress Tracking class.ilTrQuery.php executeQueries sql injection4.7
- CVE-2024-8001VIWIS LMS Print authorization5.3
- CVE-2024-37870SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to execute arbitrary SQL commands via the id parameter.9.8
- CVE-2024-37840SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the Les...8.8
- CVE-2024-5588itsourcecode Learning Management System processscore.php sql injection6.3
- CVE-2024-5519ItsourceCode Learning Management System Project In PHP login.php sql injection7.3
- CVE-2023-40607WordPress CLUEVO LMS, E-Learning Platform Plugin <= 1.10.0 is vulnerable to Cross Site Request Forgery (CSRF)4.3
- CVE-2021-25029Cluevo < 1.8.1 - Admin+ Stored Cross Site Scripting4.8
- CVE-2021-25200Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php.9.8
- CVE-2021-25201SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database information.7.5
- CVE-2018-16970Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.4.3
- CVE-2018-16971Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-purchased course contents (quiz / test) via a modified id parameter.4.3
Product normalization is registry-driven with AI assist and human review. How it works