CVE-2026-9341
- EPSS 0.26%
- Veröffentlicht 14.07.2026 11:30:42
- Zuletzt bearbeitet 14.07.2026 15:26:24
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.0 via the 'save_lesson_note', 'get_lesson_note', and 'complete_les...
CVE-2026-5348
- EPSS 0.26%
- Veröffentlicht 02.07.2026 05:35:13
- Zuletzt bearbeitet 02.07.2026 15:17:11
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.8.1. This is due to the '/topics' REST API endpoint being registered wit...
- EPSS 0.22%
- Veröffentlicht 16.06.2026 21:24:27
- Zuletzt bearbeitet 16.06.2026 21:24:27
Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue affects Academy LMS Pro: from n/a before 3.5.2.
CVE-2026-25372
- EPSS 0.21%
- Veröffentlicht 19.02.2026 08:27:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Academy LMS: from n/a through <= 3.5.3.
CVE-2025-15521
- EPSS 0.36%
- Veröffentlicht 21.01.2026 01:23:31
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly validating a us...
CVE-2025-68527
- EPSS 0.14%
- Veröffentlicht 24.12.2025 12:31:25
- Zuletzt bearbeitet 27.04.2026 19:16:28
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC Academy LMS academy allows Stored XSS.This issue affects Academy LMS: from n/a through <= 3.4.0.
CVE-2024-38701
- EPSS 0.37%
- Veröffentlicht 22.07.2024 11:15:03
- Zuletzt bearbeitet 21.11.2024 09:26:39
Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.
CVE-2024-37234
- EPSS 0.27%
- Veröffentlicht 06.07.2024 10:15:02
- Zuletzt bearbeitet 15.04.2026 00:35:42
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.
CVE-2024-32714
- EPSS 0.32%
- Veröffentlicht 09.06.2024 17:15:49
- Zuletzt bearbeitet 29.01.2025 17:24:28
Missing Authorization vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.16.
CVE-2024-35171
- EPSS 0.59%
- Veröffentlicht 14.05.2024 15:39:41
- Zuletzt bearbeitet 28.04.2026 19:25:32
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.25.