Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 20, 2026
Frappe LMS enrollment bypass in paid courses via unrelated batch
CVE-2026-39385
Description
Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.
Affected products
2Patches
Vulnerability mechanics
References
1- github.com/frappe/lms/security/advisories/GHSA-c4xh-2rcm-6mgcmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.