Lms
44 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Lms, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Lms CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 1 |
| 2025-08 | 1 |
| 2025-09 | 1 |
| 2025-10 | 7 |
| 2025-11 | 2 |
| 2025-12 | 3 |
| 2026-01 | 2 |
| 2026-02 | 2 |
| 2026-03 | 0 |
| 2026-04 | 2 |
| 2026-05 | 1 |
| 2026-06 | 5 |
| 2026-07 | 2 |
| 2026-08 | 0 |
| 2026-09 | 2 |
Severity
How the 44 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High3
- Medium27
- Low6
Latest CVEs
The 15 most recently published vulnerabilities affecting Lms.
- CVE-2026-96777Forma LMS Multi-User-Selector AJAX Endpoint getData getDataTask sql injection6.3
- CVE-2026-54343Frappe LMS: Path Traversal in SCORM File Serving—
- CVE-2026-39385Frappe LMS enrollment bypass in paid courses via unrelated batch—
- CVE-2026-27404WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-40457Reflected XSS in LMS—
- CVE-2026-40456OS Command Injection in LMS—
- CVE-2026-40455SQL Injection in LMS—
- CVE-2026-46546Frappe LMS: HTML injection in user-controlled metadata5.4
- CVE-2026-48559Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags5.4
- CVE-2026-39405Frappe has Path Transversal via SCORM—
- CVE-2026-39415Frappe Learning Management System has Client-Side Manipulation of Quiz Scores4.3
- CVE-2026-34606Stored XSS in Frappe LMS6.1
- CVE-2026-26977Frappe Learning Management System exposes details of unpublished courses to unauthorized users5.3
- CVE-2026-26031Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students5.3
- CVE-2026-1106Chamilo LMS Legal Consent SocialController.php deleteLegal improper authorization5.4
Product grouping is registry-driven, with AI assist and human review. How it works