Frappe
Frappe Learning: vulnerabilidades y CVE
Frappe Learning tiene 22 vulnerabilidades publicadas, 18 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses18
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-46546 | Baja (2.1) | 0.23% | — | 10 jun 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain user-editable… |
| CVE-2026-39415 | Media (5.3) | 0.28% | — | 8 abr 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0, a vulnerability has been identified in Frappe Learning where quiz scores can be modified by… |
| CVE-2026-34606 | Media (6.9) | 0.33% | — | 2 abr 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issue has been patched… |
| CVE-2026-26977 | Media (6.9) | 0.33% | — | 20 feb 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API… |
| CVE-2026-26031 | Baja (1.3) | 0.30% | — | 11 feb 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified in Frappe Learning, where unauthorised users were able to access the… |
| CVE-2026-23497 | Baja (1.3) | 0.17% | — | 14 ene 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and earlier, there is a stored XSS vulnerability where a specially crafted image filename could execute… |
| CVE-2025-67734 | Media (5.1) | 0.17% | — | 12 dic 2025 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated attackers to enter JavaScript through the Company Website field of… |
| CVE-2025-67730 | Media (5.1) | 0.17% | — | 12 dic 2025 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated users to add malicious HTML and JavaScript through description fields… |
| CVE-2025-66581 | Baja (1.3) | 0.21% | — | 5 dic 2025 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side authorization logic allowed authenticated users to perform actions beyond… |
| CVE-2025-64707 | Baja (1.2) | 0.17% | — | 12 nov 2025 | Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, when admins revoked a role from the user, the effect was not immediate because of… |
| CVE-2025-64705 | Baja (1.3) | 0.21% | — | 12 nov 2025 | Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, users were able to access the submissions made by other students The issue has been… |
| CVE-2025-62779 | Baja (1.2) | 0.18% | — | 27 oct 2025 | Frappe Learning is a learning system that helps users structure their content. In Frappe Learning 2.39.1 and earlier, users were able to add HTML through input fields in the Job Form. |
| CVE-2025-62778 | Baja (1.3) | 0.22% | — | 27 oct 2025 | Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to access the Quiz Form if they had the URL. |
| CVE-2025-62158 | Baja (2.7) | 0.29% | — | 10 oct 2025 | Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue… |
| CVE-2025-11283 | Baja (1.9) | 0.41% | — | 5 oct 2025 | A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. Executing manipulation of the argument Description can lead to cross site scripting. The attack can… |
| CVE-2025-11282 | Baja (1.9) | 0.39% | — | 5 oct 2025 | A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Incomplete Fix CVE-2025-55006. Performing a manipulation results in cross site scripting. Remote… |
| CVE-2025-11281 | Baja (1.3) | 0.36% | — | 5 oct 2025 | A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course Handler. Such manipulation leads to improper access controls.… |
| CVE-2025-11280 | Baja (2.9) | 0.48% | — | 5 oct 2025 | A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/ of the component Assignment Picture Handler. This manipulation causes direct request. The attack may be initiated remotely.… |
| CVE-2025-59415 | Media (5.4) | 0.24% | — | 17 sept 2025 | Frappe Learning is a learning system that helps users structure their content. In versions 2.34.1 and below, there is a security vulnerability in Frappe Learning where the system did not adequately sanitize the content… |
| CVE-2025-55006 | Alta (8.8) | 0.26% | — | 9 ago 2025 | Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately sanitize uploaded SVG files. This allowed users to upload… |
| CVE-2023-5555 | Media (6.1) | 0.44% | — | 12 oct 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4. |
| CVE-2023-42807 | Crítica (9.8) | 0.40% | — | 21 sept 2023 | Frappe LMS is an open source learning management system. In versions 1.0.0 and prior, on the People Page of LMS, there was an SQL Injection vulnerability. The issue has been fixed in the `main` branch. Users won't face… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.