High severityNVD Advisory· Published Jul 20, 2026· Updated Jul 22, 2026
CVE-2026-39385
CVE-2026-39385
Description
Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.