Frappe / Learning
22 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-46546 | Frappe LMS: HTML injection in user-controlled metadata | LOW | 2.1 | Jun 9, 2026 |
| CVE-2026-39415 | Frappe Learning Management System has Client-Side Manipulation of Quiz Scores | MEDIUM | 5.3 | Apr 8, 2026 |
| CVE-2026-34606 | Stored XSS in Frappe LMS | MEDIUM | 6.9 | Apr 2, 2026 |
| CVE-2026-26977 | Frappe Learning Management System exposes details of unpublished courses to unauthorized users | MEDIUM | 6.9 | Feb 20, 2026 |
| CVE-2026-26031 | Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students | LOW | 1.3 | Feb 11, 2026 |
| CVE-2026-23497 | Frappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs Pages | LOW | 1.3 | Jan 14, 2026 |
| CVE-2025-67734 | Frappe Authenticated Users can Execute JavaScript through its Job Form | MEDIUM | 5.1 | Dec 12, 2025 |
| CVE-2025-67730 | Frappe authenticated users can execute XSS through form description fields | MEDIUM | 5.1 | Dec 12, 2025 |
| CVE-2025-66581 | Frappe LMS is Missing Server-Side Authorization in Business Logic | LOW | 1.3 | Dec 5, 2025 |
| CVE-2025-64707 | Frappe LMS revoking access did not show immediate effect as roles were cached | LOW | 1.2 | Nov 12, 2025 |
| CVE-2025-64705 | Frappe user was able to access the submission of other students | LOW | 1.3 | Nov 12, 2025 |
| CVE-2025-62779 | Frappe Learning users were able to add HTML through input fields in the Job Form | LOW | 1.2 | Oct 27, 2025 |
| CVE-2025-62778 | Frappe Learning allowed students to access the Quiz Form via direct URL | LOW | 1.3 | Oct 27, 2025 |
| CVE-2025-62158 | Frappe had attachments made by students to their assignments of type Text set to public | LOW | 2.7 | Oct 10, 2025 |
| CVE-2025-11283 | Frappe LMS Course cross site scripting | MEDIUM | 4.8 | Oct 5, 2025 |
| CVE-2025-11282 | Frappe LMS Incomplete Fix CVE-2025-55006 cross site scripting | MEDIUM | 4.8 | Oct 5, 2025 |
| CVE-2025-11281 | Frappe LMS Unpublished Course courses access control | LOW | 2.3 | Oct 5, 2025 |
| CVE-2025-11280 | Frappe LMS Assignment Picture files direct request | MEDIUM | 6.3 | Oct 5, 2025 |
| CVE-2025-59415 | Frappe Learning vulnerable to Malicious Content upload via Profile bio field | MEDIUM | 5.4 | Sep 17, 2025 |
| CVE-2025-55006 | Frappe Learning Holds Potential for Malicious SVG Upload in Image Upload Feature | HIGH | 8.8 | Aug 9, 2025 |
| CVE-2023-5555 | Cross-site Scripting (XSS) - Generic in frappe/lms | MEDIUM | 6.1 | Oct 12, 2023 |
| CVE-2023-42807 | Frappe LMS SQL Injection Issue on People Page | CRITICAL | 9.8 | Sep 21, 2023 |
Showing 1 to 22 of 22 CVEs