CVE-2026-25372
- EPSS 0.03%
- Veröffentlicht 19.02.2026 08:27:00
- Zuletzt bearbeitet 19.02.2026 20:25:38
Missing Authorization vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Academy LMS: from n/a through <= 3.5.3.
CVE-2025-15521
- EPSS 0.14%
- Veröffentlicht 21.01.2026 01:23:31
- Zuletzt bearbeitet 26.01.2026 15:04:59
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly validating a us...
CVE-2025-68527
- EPSS 0.04%
- Veröffentlicht 24.12.2025 12:31:25
- Zuletzt bearbeitet 20.01.2026 15:19:44
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC Academy LMS academy allows Stored XSS.This issue affects Academy LMS: from n/a through <= 3.4.0.
CVE-2024-38701
- EPSS 0.06%
- Veröffentlicht 22.07.2024 11:15:03
- Zuletzt bearbeitet 21.11.2024 09:26:39
Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.
CVE-2024-37234
- EPSS 0.16%
- Veröffentlicht 06.07.2024 10:15:02
- Zuletzt bearbeitet 21.11.2024 09:23:27
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.
CVE-2024-32714
- EPSS 0.22%
- Veröffentlicht 09.06.2024 17:15:49
- Zuletzt bearbeitet 29.01.2025 17:24:28
Missing Authorization vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.16.
CVE-2024-35171
- EPSS 0.32%
- Veröffentlicht 14.05.2024 15:39:41
- Zuletzt bearbeitet 27.01.2025 18:08:26
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.25.
CVE-2024-33912
- EPSS 0.34%
- Veröffentlicht 06.05.2024 19:15:07
- Zuletzt bearbeitet 03.02.2025 19:05:39
Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.
CVE-2024-1505
- EPSS 0.13%
- Veröffentlicht 13.03.2024 16:15:23
- Zuletzt bearbeitet 22.01.2025 20:57:20
The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved...