Vulnerabilities
Vulnerable Software
Frappe:  >> Learning  >> 2.43.0  Security Vulnerabilities
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issue has been patched in version 2.48.0.
CVSS Score
6.1
EPSS Score
0.0
Published
2026-04-02
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API endpoints. A fix for this issue is planned for the 2.45.0 release.
CVSS Score
5.3
EPSS Score
0.0
Published
2026-02-20
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified in Frappe Learning, where unauthorised users were able to access the full list of enrolled students (by email) in batches. This vulnerability is fixed in 2.44.0.
CVSS Score
5.3
EPSS Score
0.0
Published
2026-02-11
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and earlier, there is a stored XSS vulnerability where a specially crafted image filename could execute malicious JavaScript when rendered on course or jobs pages.
CVSS Score
5.4
EPSS Score
0.0
Published
2026-01-14


Contact Us

Shodan ® - All rights reserved