Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Formalms MEDIUM 5.3
CVE-2026-26744

A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The…

Fix: after 4.1.18
Fix from $1,600 2026-02-19
Formalms MEDIUM 6.1
CVE-2023-46693

Cross Site Scripting (XSS) vulnerability in FormaLMS before 4.0.5 allows attackers to run arbitrary code via title parameters.

Fix: 4.0.5+
Fix from $1,600 2023-12-07
Formalms HIGH 8.8
CVE-2022-41681

There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege es…

Fix: 3.2.1+
Fix from $1,950 2022-10-31
Formalms HIGH 8.8
CVE-2022-42923

Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an auth…

Fix: 3.2.1+
Fix from $1,950 2022-10-31
Formalms HIGH 8.8
CVE-2022-42925

There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege es…

Fix: 3.2.1+
Fix from $1,950 2022-10-31
Formalms MEDIUM 6.5
CVE-2022-41680

Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an auth…

Fix: 3.2.1+
Fix from $1,600 2022-10-31
Formalms MEDIUM 6.5
CVE-2022-42924

Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an auth…

Fix: 3.2.1+
Fix from $1,600 2022-10-31
Formalms MEDIUM 6.1
CVE-2022-41679

Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker to inject javascript co…

Fix: 3.2.1+
Fix from $1,600 2022-10-31
Formalms CRITICAL 9.8
CVE-2022-27104

An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.

Fix: 1.4.3+
Fix from $2,300 2022-04-19
Formalms CRITICAL 9.8
CVE-2021-43136EPSS 16%

An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platfo…

Fix: after 2.4.4
Fix from $2,300 2021-11-10
Formalms HIGH 8.8
CVE-2020-26802

forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=saveinfo via a GET request to …

No fix yet
Fix from $1,950 2020-10-08
Formalms HIGH 8.8
CVE-2019-5110

Exploitable SQL injection vulnerabilities exist in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause SQL injecti…

No fix yet
Fix from $1,950 2019-12-03
Formalms HIGH 8.8
CVE-2019-5111

Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_…

No fix yet
Fix from $1,950 2019-12-03
Formalms HIGH 8.8
CVE-2019-5112

Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_…

No fix yet
Fix from $1,950 2019-12-03
Formalms HIGH 8.8
CVE-2019-5109

Exploitable SQL injection vulnerabilities exists in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause SQL inject…

No fix yet
Fix from $1,950 2019-12-03