VYPR
Vendor

Academy LMS

Products
2
CVEs
10
Across products
10
Status
Private

Products

2

Recent CVEs

10
  • CVE-2022-47132HigFeb 3, 2023
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.

  • CVE-2023-4974MedSep 15, 2023
    risk 0.41cvss 6.3epss 0.05

    A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument price_min/price_max leads to sql…

  • CVE-2023-53876MedDec 15, 2025
    risk 0.35cvss 5.4epss 0.00

    Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and…

  • CVE-2023-4119MedAug 3, 2023
    risk 0.31cvss 4.3epss 0.04

    A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code of the file /academy/home/courses. The manipulation of the argument query/sort_by leads to cross site scripting. The attack can be initiated remotely.…

  • CVE-2022-47131MedFeb 3, 2023
    risk 0.31cvss 4.8epss 0.00

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.

  • CVE-2022-29380MedMay 25, 2022
    risk 0.31cvss 4.8epss 0.01

    Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.

  • CVE-2024-38701MedJul 22, 2024
    risk 0.28cvss 4.3epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.

  • CVE-2024-32714MedJun 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.16.

  • CVE-2022-47130MedFeb 3, 2023
    risk 0.28cvss 4.3epss 0.01

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page.

  • CVE-2023-4973LowSep 15, 2023
    risk 0.23cvss 3.5epss 0.02

    A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument…