All 40 CVE vulnerabilities found in lms, with AI-generated Chinese analysis, references, and POCs.
This page aggregates security vulnerabilities associated with the Learning Management System (LMS) product category, focusing on general software weakness types without targeting a specific vendor implementation. The content covers a broad spectrum of Common Weakness Enumeration (CWE) classifications and associated CVE entries, spanning from early foundational releases through to recent updates, ensuring a comprehensive historical perspective on security flaws. Readers can utilize this resource to systematically track vendor advisories across different LMS providers, gaining insight into how specific vendors respond to critical patches. Additionally, the page allows users to understand the prevalence and impact of specific weakness classes within learning platforms, helping security teams identify recurring patterns in code quality or configuration errors. By examining the vulnerability history of specific products, administrators can benchmark their own systems against industry trends and prioritize remediation efforts based on severity and exploitability. This aggregation serves as a central reference point for security researchers, IT directors, and compliance officers who need to assess the risk posture of educational technology infrastructure. The data is structured to facilitate easy searching by product name, vendor, or vulnerability type, enabling efficient cross-referencing between different systems. Whether you are conducting a routine audit or investigating a specific incident, this page provides the necessary context to make informed decisions about software procurement and maintenance. It highlights the evolving landscape of LMS security, reflecting the increasing focus on protecting sensitive student data and institutional information from cyber threats.
Vendor: Fernus Informatics
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-8002 | VIWIS LMS File Upload cross site scripting CWE-79 | 4.3 | Medium | 2025-01-08 |
| CVE-2024-8001 | VIWIS LMS Print authorization CWE-862 | 5.3 | Medium | 2024-11-13 |
| CVE-2024-3932 | Totara LMS User Selector cross-site request forgery CWE-352 | 3.1 | Low | 2024-04-18 |
| CVE-2024-3931 | Totara LMS User Selector check.php cross site scripting CWE-79 | 3.5 | Low | 2024-04-18 |
| CVE-2024-1439 | Inadequate access control vulnerability in Moodle CWE-284 | 6.5 | Medium | 2024-02-12 |
| CVE-2023-42807 | Frappe LMS SQL Injection Issue on People Page CWE-89 | 6.3 | Medium | 2023-09-21 |
| CVE-2023-4974 | Academy LMS GET Parameter filter sql injection CWE-89 | 6.3 | Medium | 2023-09-15 |
| CVE-2023-4973 | Academy LMS GET Parameter filter cross site scripting CWE-79 | 3.5 | Low | 2023-09-15 |
| CVE-2023-4119 | Academy LMS courses cross site scripting CWE-79 | 4.3 | Medium | 2023-08-03 |
| CVE-2023-1728 | Unrestricted Upload of File with Dangerous Type in Fernus LMS CWE-434 | 9.8 | Critical | 2023-04-04 |
All 40 known CVE vulnerabilities affecting lms with full Chinese analysis, references, and POCs where available.