VYPR
Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 20, 2026

Frappe LMS enrollment bypass in paid courses via unrelated batch

CVE-2026-39385

Description

Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.