Learning
22 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Learning, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Learning CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 1 |
| 2025-10 | 7 |
| 2025-11 | 2 |
| 2025-12 | 3 |
| 2026-01 | 1 |
| 2026-02 | 2 |
| 2026-03 | 0 |
| 2026-04 | 2 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 22 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Medium19
- Low3
Latest CVEs
The 15 most recently published vulnerabilities affecting Learning.
- CVE-2026-46546Frappe LMS: HTML injection in user-controlled metadata5.4
- CVE-2026-39415Frappe Learning Management System has Client-Side Manipulation of Quiz Scores4.3
- CVE-2026-34606Stored XSS in Frappe LMS6.1
- CVE-2026-26977Frappe Learning Management System exposes details of unpublished courses to unauthorized users5.3
- CVE-2026-26031Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students5.3
- CVE-2026-23497Frappe LMS has a Stored XSS via Unsanitized Image Filename in Course and Jobs Pages5.4
- CVE-2025-67734Frappe Authenticated Users can Execute JavaScript through its Job Form5.4
- CVE-2025-67730Frappe authenticated users can execute XSS through form description fields5.4
- CVE-2025-66581Frappe LMS is Missing Server-Side Authorization in Business Logic6.5
- CVE-2025-64707Frappe LMS revoking access did not show immediate effect as roles were cached5.4
- CVE-2025-64705Frappe user was able to access the submission of other students4.3
- CVE-2025-62779Frappe Learning users were able to add HTML through input fields in the Job Form5.4
- CVE-2025-62778Frappe Learning allowed students to access the Quiz Form via direct URL5.3
- CVE-2025-62158Frappe had attachments made by students to their assignments of type Text set to public5.3
- CVE-2025-11283Frappe LMS Course cross site scripting2.4
Product grouping is registry-driven, with AI assist and human review. How it works