{"schema_version":1,"title":"Frappe Technologies LMS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in Frappe Technologies LMS: 0 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-88844, was published on 18 September 2026.","url":"https://junglewise.ai/threats/technologies/lms","json_url":"https://junglewise.ai/threats/technologies/lms.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/lms","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":12,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":9,"last_90_days":9,"last_365_days":12},"latest":[{"cve":"CVE-2026-88844","cvss":2.7,"epss":0.003,"slug":"cve-2026-88844-masterstudy-lms-insecure-direct-object-reference-in-course","title":"MasterStudy LMS insecure direct object reference in course enrollment data","severity":"low","exploited":false,"published_at":"2026-09-18T06:16:41.267+00:00","url":"https://junglewise.ai/threats/cve-2026-88844-masterstudy-lms-insecure-direct-object-reference-in-course"},{"cve":"CVE-2026-81340","cvss":3.8,"epss":0.0032,"slug":"cve-2026-81340-masterstudy-lms-privilege-escalation-via-rest-api-idor","title":"MasterStudy LMS privilege escalation via REST API IDOR","severity":"low","exploited":false,"published_at":"2026-09-18T06:16:39.073+00:00","url":"https://junglewise.ai/threats/cve-2026-81340-masterstudy-lms-privilege-escalation-via-rest-api-idor"},{"cve":"CVE-2026-82851","cvss":2.7,"epss":0.003,"slug":"cve-2026-82851-masteriyo-lms-arbitrary-post-disclosure-via-idor","title":"Masteriyo LMS arbitrary post disclosure via IDOR","severity":"low","exploited":false,"published_at":"2026-09-12T06:16:26.253+00:00","url":"https://junglewise.ai/threats/cve-2026-82851-masteriyo-lms-arbitrary-post-disclosure-via-idor"},{"cve":"CVE-2026-82848","cvss":5.3,"epss":0.0032,"slug":"cve-2026-82848-masteriyo-lms-authorization-bypass-in-rest-api-course-enrollment","title":"Masteriyo LMS authorization bypass in REST API course enrollment endpoint","severity":"medium","exploited":false,"published_at":"2026-09-09T06:17:17.453+00:00","url":"https://junglewise.ai/threats/cve-2026-82848-masteriyo-lms-authorization-bypass-in-rest-api-course-enrollment"},{"cve":"CVE-2026-82846","cvss":6.8,"epss":0.0043,"slug":"cve-2026-82846-masteriyo-lms-stored-cross-site-scripting-in-course-custom-fields","title":"Masteriyo LMS stored cross-site scripting in course custom fields","severity":"medium","exploited":false,"published_at":"2026-09-05T07:17:13.187+00:00","url":"https://junglewise.ai/threats/cve-2026-82846-masteriyo-lms-stored-cross-site-scripting-in-course-custom-fields"},{"cve":"CVE-2026-81198","cvss":3.8,"epss":0.0032,"slug":"cve-2026-81198-masterstudy-lms-privilege-escalation-via-idor-in-curriculum","title":"MasterStudy LMS privilege escalation via IDOR in curriculum","severity":"low","exploited":false,"published_at":"2026-09-02T06:17:18.967+00:00","url":"https://junglewise.ai/threats/cve-2026-81198-masterstudy-lms-privilege-escalation-via-idor-in-curriculum"},{"cve":"CVE-2026-81196","cvss":2.7,"epss":0.003,"slug":"cve-2026-81196-masterstudy-lms-wordpress-plugin-idor-in-quiz-question-access","title":"MasterStudy LMS WordPress plugin IDOR in quiz question access","severity":"low","exploited":false,"published_at":"2026-09-02T06:17:18.777+00:00","url":"https://junglewise.ai/threats/cve-2026-81196-masterstudy-lms-wordpress-plugin-idor-in-quiz-question-access"},{"cve":"CVE-2026-81342","cvss":4.7,"epss":0.0029,"slug":"cve-2026-81342-masterstudy-lms-open-redirect-in-user-registration","title":"MasterStudy LMS open redirect in user registration","severity":"medium","exploited":false,"published_at":"2026-08-29T06:17:58.7+00:00","url":"https://junglewise.ai/threats/cve-2026-81342-masterstudy-lms-open-redirect-in-user-registration"},{"cve":"CVE-2026-81026","cvss":4.8,"epss":0.0022,"slug":"cve-2026-81026-masterstudy-lms-payment-verification-bypass-in-paypal-ipn-handler","title":"MasterStudy LMS payment verification bypass in PayPal IPN handler","severity":"medium","exploited":false,"published_at":"2026-08-29T06:17:55.99+00:00","url":"https://junglewise.ai/threats/cve-2026-81026-masterstudy-lms-payment-verification-bypass-in-paypal-ipn-handler"},{"cve":"CVE-2026-39405","cvss":9.4,"slug":"cve-2026-39405-frappe-lms-path-traversal-in-scorm-zip-upload","title":"Frappe LMS path traversal in SCORM ZIP upload","severity":"info","exploited":false,"published_at":"2026-05-20T20:16:39.697+00:00","url":"https://junglewise.ai/threats/cve-2026-39405-frappe-lms-path-traversal-in-scorm-zip-upload"},{"cve":"CVE-2026-39415","cvss":4.3,"epss":0.0026,"slug":"cve-2026-39415-frappe-lms-client-side-quiz-score-manipulation","title":"Frappe LMS client-side quiz score manipulation","severity":"medium","exploited":false,"published_at":"2026-04-08T21:16:59.033+00:00","url":"https://junglewise.ai/threats/cve-2026-39415-frappe-lms-client-side-quiz-score-manipulation"},{"cve":"CVE-2026-34606","cvss":6.1,"epss":0.0019,"slug":"cve-2026-34606-frappe-lms-stored-xss-in-lesson-content","title":"Frappe LMS stored XSS in lesson content","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:32.17+00:00","url":"https://junglewise.ai/threats/cve-2026-34606-frappe-lms-stored-xss-in-lesson-content"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Frappe Technologies Frappe Framework","slug":"frappe-framework","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/frappe-framework"}],"technology":{"hub":true,"name":"Frappe Technologies LMS","slug":"lms","vendor":{"name":"Frappe Technologies","slug":"frappe-technologies","url":"https://junglewise.ai/threats/vendors/frappe-technologies"},"aliases":[],"category":"web-application","homepage":"https://frappelms.com/","repo_url":"https://github.com/frappe/lms","description":"An open-source learning management system built on the Frappe framework.","url":"https://junglewise.ai/threats/technologies/lms"},"most_severe":[{"cve":"CVE-2026-82846","cvss":6.8,"epss":0.0043,"slug":"cve-2026-82846-masteriyo-lms-stored-cross-site-scripting-in-course-custom-fields","title":"Masteriyo LMS stored cross-site scripting in course custom fields","severity":"medium","exploited":false,"published_at":"2026-09-05T07:17:13.187+00:00","url":"https://junglewise.ai/threats/cve-2026-82846-masteriyo-lms-stored-cross-site-scripting-in-course-custom-fields"},{"cve":"CVE-2026-34606","cvss":6.1,"epss":0.0019,"slug":"cve-2026-34606-frappe-lms-stored-xss-in-lesson-content","title":"Frappe LMS stored XSS in lesson content","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:32.17+00:00","url":"https://junglewise.ai/threats/cve-2026-34606-frappe-lms-stored-xss-in-lesson-content"},{"cve":"CVE-2026-82848","cvss":5.3,"epss":0.0032,"slug":"cve-2026-82848-masteriyo-lms-authorization-bypass-in-rest-api-course-enrollment","title":"Masteriyo LMS authorization bypass in REST API course enrollment endpoint","severity":"medium","exploited":false,"published_at":"2026-09-09T06:17:17.453+00:00","url":"https://junglewise.ai/threats/cve-2026-82848-masteriyo-lms-authorization-bypass-in-rest-api-course-enrollment"},{"cve":"CVE-2026-81026","cvss":4.8,"epss":0.0022,"slug":"cve-2026-81026-masterstudy-lms-payment-verification-bypass-in-paypal-ipn-handler","title":"MasterStudy LMS payment verification bypass in PayPal IPN handler","severity":"medium","exploited":false,"published_at":"2026-08-29T06:17:55.99+00:00","url":"https://junglewise.ai/threats/cve-2026-81026-masterstudy-lms-payment-verification-bypass-in-paypal-ipn-handler"},{"cve":"CVE-2026-81342","cvss":4.7,"epss":0.0029,"slug":"cve-2026-81342-masterstudy-lms-open-redirect-in-user-registration","title":"MasterStudy LMS open redirect in user registration","severity":"medium","exploited":false,"published_at":"2026-08-29T06:17:58.7+00:00","url":"https://junglewise.ai/threats/cve-2026-81342-masterstudy-lms-open-redirect-in-user-registration"},{"cve":"CVE-2026-39415","cvss":4.3,"epss":0.0026,"slug":"cve-2026-39415-frappe-lms-client-side-quiz-score-manipulation","title":"Frappe LMS client-side quiz score manipulation","severity":"medium","exploited":false,"published_at":"2026-04-08T21:16:59.033+00:00","url":"https://junglewise.ai/threats/cve-2026-39415-frappe-lms-client-side-quiz-score-manipulation"},{"cve":"CVE-2026-81340","cvss":3.8,"epss":0.0032,"slug":"cve-2026-81340-masterstudy-lms-privilege-escalation-via-rest-api-idor","title":"MasterStudy LMS privilege escalation via REST API IDOR","severity":"low","exploited":false,"published_at":"2026-09-18T06:16:39.073+00:00","url":"https://junglewise.ai/threats/cve-2026-81340-masterstudy-lms-privilege-escalation-via-rest-api-idor"},{"cve":"CVE-2026-81198","cvss":3.8,"epss":0.0032,"slug":"cve-2026-81198-masterstudy-lms-privilege-escalation-via-idor-in-curriculum","title":"MasterStudy LMS privilege escalation via IDOR in curriculum","severity":"low","exploited":false,"published_at":"2026-09-02T06:17:18.967+00:00","url":"https://junglewise.ai/threats/cve-2026-81198-masterstudy-lms-privilege-escalation-via-idor-in-curriculum"},{"cve":"CVE-2026-88844","cvss":2.7,"epss":0.003,"slug":"cve-2026-88844-masterstudy-lms-insecure-direct-object-reference-in-course","title":"MasterStudy LMS insecure direct object reference in course enrollment data","severity":"low","exploited":false,"published_at":"2026-09-18T06:16:41.267+00:00","url":"https://junglewise.ai/threats/cve-2026-88844-masterstudy-lms-insecure-direct-object-reference-in-course"},{"cve":"CVE-2026-82851","cvss":2.7,"epss":0.003,"slug":"cve-2026-82851-masteriyo-lms-arbitrary-post-disclosure-via-idor","title":"Masteriyo LMS arbitrary post disclosure via IDOR","severity":"low","exploited":false,"published_at":"2026-09-12T06:16:26.253+00:00","url":"https://junglewise.ai/threats/cve-2026-82851-masteriyo-lms-arbitrary-post-disclosure-via-idor"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}