Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-26744 A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The… Formalms after 4.1.18 Fix from $1,6002026-02-19 MEDIUM 6.1 CVE-2023-46693 Cross Site Scripting (XSS) vulnerability in FormaLMS before 4.0.5 allows attackers to run arbitrary code via title parameters. Formalms 4.0.5+ Fix from $1,6002023-12-07 HIGH 8.8 CVE-2022-41681 There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege es… Formalms 3.2.1+ Fix from $1,9502022-10-31 HIGH 8.8 CVE-2022-42923 Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an auth… Formalms 3.2.1+ Fix from $1,9502022-10-31 HIGH 8.8 CVE-2022-42925 There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege es… Formalms 3.2.1+ Fix from $1,9502022-10-31 MEDIUM 6.5 CVE-2022-41680 Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an auth… Formalms 3.2.1+ Fix from $1,6002022-10-31 MEDIUM 6.5 CVE-2022-42924 Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an auth… Formalms 3.2.1+ Fix from $1,6002022-10-31 MEDIUM 6.1 CVE-2022-41679 Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker to inject javascript co… Formalms 3.2.1+ Fix from $1,6002022-10-31 CRITICAL 9.8 CVE-2022-27104 An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3. Formalms 1.4.3+ Fix from $2,3002022-04-19 CRITICAL 9.8 CVE-2021-43136EPSS 16% An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platfo… Formalms after 2.4.4 Fix from $2,3002021-11-10 HIGH 8.8 CVE-2020-26802 forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=saveinfo via a GET request to … Formalms No fix yet Fix from $1,9502020-10-08 HIGH 8.8 CVE-2019-5110 Exploitable SQL injection vulnerabilities exist in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause SQL injecti… Formalms No fix yet Fix from $1,9502019-12-03 HIGH 8.8 CVE-2019-5111 Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_… Formalms No fix yet Fix from $1,9502019-12-03 HIGH 8.8 CVE-2019-5112 Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_… Formalms No fix yet Fix from $1,9502019-12-03 HIGH 8.8 CVE-2019-5109 Exploitable SQL injection vulnerabilities exists in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause SQL inject… Formalms No fix yet Fix from $1,9502019-12-03