VYPR
High severityNVD Advisory· Published Jul 20, 2026· Updated Jul 22, 2026

CVE-2026-39385

CVE-2026-39385

Description

Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.