Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/epoupon/lms

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.

Join the discussion

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL. This issue has been patched in version 2.53.0.

Join the discussion

Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victim's library, causing the payload to be saved during library scanning and executed automatically in the web interface due to tag content being rendered using Wt::TextFormat::UnsafeXHTML without sanitization in src/lms/ui/Utils.cpp.

Join the discussion

A path traversal vulnerability (CWE-22) exists in Frappe Learning Management System (LMS) versions 2.50.0 and below. A user with the course editing role could upload a SCORM ZIP package that writes files outside the intended directory. This vulnerability allows unauthorized file writes beyond restricted directories. The issue is resolved in version 2.50.1.

Join the discussion

Frappe Learning Management System (LMS) versions prior to 2.46.0 have a vulnerability where quiz scores are calculated and enforced on the client side. This allows students to modify their quiz scores using browser developer tools before submission, compromising the integrity of quiz results. The vulnerability does not allow unauthorized access to other users' data or privilege escalation. The issue is fixed in version 2.46.0.

Join the discussion

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issue has been patched in version 2.48.0.

Join the discussion

CVE-2026-23497 is a stored cross-site scripting (XSS) vulnerability in Frappe Learning Management System (LMS) versions 2.44.0 and earlier. The flaw arises from improper neutralization of input, specifically in image filenames, which can lead to execution of malicious JavaScript when these filenames are rendered on course or jobs pages. Although the CVSS 4.0 score is low (1.3), the vulnerability does not require privileges or authentication but does require user interaction. No known exploits are currently reported in the wild. European organizations using Frappe LMS should be aware of this issue and apply mitigations to prevent potential exploitation, especially in environments where user-generated content is displayed. The impact is limited by the low severity and the need for user interaction, but stored XSS can still lead to session hijacking or defacement if exploited.

Join the discussion

CVE-2025-67734 is a medium-severity cross-site scripting (XSS) vulnerability in the Frappe Learning Management System (LMS) versions prior to 2.42.0. Authenticated attackers can inject malicious JavaScript code via the Company Website field in the Job Form. This script executes in the browsers of users who view the affected job postings, potentially compromising user data or session integrity. The vulnerability requires attacker authentication but no user interaction beyond viewing the malicious content. It has a CVSS score of 5.1, reflecting moderate impact and ease of exploitation. The issue is resolved in version 2.42.

Join the discussion

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated users to add malicious HTML and JavaScript through description fields in the Job, Course and Batch forms. This issue is fixed in version 2.42.0.

Join the discussion

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side authorization logic allowed authenticated users to perform actions beyond their assigned roles across multiple features. Because the affected endpoints relied on client-side or UI-level checks instead of enforcing permissions on the server, users with low-privileged roles (such as students) could perform operations intended only for instructors or administrators via directly using the API's. This vulnerability is fixed in 2.41.0.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Package: pkg:github/epoupon/lms
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses