Vulnerabilities
Vulnerable Software
Formalms:  >> Formalms  >> 3.2.1  Security Vulnerabilities
A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The application returns different error messages for valid and invalid usernames allowing an unauthenticated attacker to determine which usernames are registered in the system through observable response discrepancy.
CVSS Score
5.3
EPSS Score
0.0
Published
2026-02-19
Cross Site Scripting (XSS) vulnerability in FormaLMS before 4.0.5 allows attackers to run arbitrary code via title parameters.
CVSS Score
6.1
EPSS Score
0.002
Published
2023-12-07


Contact Us

Shodan ® - All rights reserved