Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lifterlms CRITICAL 9.8
CVE-2025-52717

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chrisbadgett LifterLMS lifterlms allows SQL Inj…

Fix: 8.0.7+
Fix from $2,300 2025-06-27
Lifterlms MEDIUM 6.1
CVE-2024-13619

The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected C…

Fix: 8.0.1+
Fix from $1,600 2025-05-15
Lifterlms MEDIUM 5.3
CVE-2025-2290

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing …

Fix: 8.0.2+
Fix from $1,600 2025-03-19
Lifterlms HIGH 7.2
CVE-2024-7349

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter i…

Fix: 7.7.6+
Fix from $1,950 2024-09-06
Lifterlms HIGH 8.8
CVE-2024-4743

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to SQL Injection via the orderBy attribute of the lifterlms_fav…

Fix: 7.6.3+
Fix from $1,950 2024-06-05
Lifterlms HIGH 8.8
CVE-2024-31363

Cross-Site Request Forgery (CSRF) vulnerability in LifterLMS.This issue affects LifterLMS: from n/a through 7.5.0.

Fix: 7.5.1+
Fix from $1,950 2024-04-12
Lifterlms MEDIUM 5.3
CVE-2024-0377

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit…

Fix: 7.5.2+
Fix from $1,600 2024-03-13
Lifterlms MEDIUM 6.7
CVE-2023-6160

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 7.4.2 …

Fix: after 7.4.2
Fix from $1,600 2023-11-22
Lifterlms MEDIUM 6.1
CVE-2022-1250

The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirmation page before outputting …

Fix: 1.4.0+
Fix from $1,600 2022-05-02
Lifterlms HIGH 7.5
CVE-2021-24562

The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue…

Fix: 4.21.2+
Fix from $1,950 2021-08-23
Lifterlms MEDIUM 5.4
CVE-2021-24308

The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plug…

Fix: 4.21.1+
Fix from $1,600 2021-05-24
Lifterlms CRITICAL 9.8
CVE-2020-6008

LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution

Fix: 3.37.15+
Fix from $2,300 2020-03-31
Lifterlms CRITICAL 9.8
CVE-2019-15896EPSS 7%

An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is…

Fix: after 3.34.5
Fix from $2,300 2019-09-10