Skip to content
Noroxi

LearnDash records

11 published records for vendor learndash.

All records

11 records
  • LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.

    CriticalCVSS 9.8No exploitEPSS 2%

    learndash · learndashApr 1, 2020

  • CVE-2023-3105
    36Monitor

    LearnDash LMS <= 4.6.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change

    HighCVSS 8.8No exploitEPSS 2%

    learndash · learndashJul 12, 2023

  • WordPress LearnDash LMS Plugin <= 4.5.3 is vulnerable to SQL Injection

    HighCVSS 8.8No exploitEPSS 1%

    learndash · learndashOct 31, 2023

  • LearnDash < 2.5.4 - Unauthenticated Arbitrary File Upload

    HighCVSS 7.5No exploitEPSS 2%

    learndash · learndashNov 1, 2021

  • An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file upl

    HighCVSS 7.5No exploitEPSS 1%

    learndash · learndashFeb 12, 2025

  • CVE-2024-1208
    23Monitor

    LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API

    MediumCVSS 5.3Proof of conceptEPSS 5%

    learndash · learndashFeb 5, 2024

  • CVE-2020-7108
    22Monitor

    The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.

    MediumCVSS 5.4Proof of conceptEPSS 3%

    learndash · learndashJan 16, 2020

  • CVE-2024-1209
    22Monitor

    LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignments

    MediumCVSS 5.3Proof of conceptEPSS 2%

    learndash · learndashFeb 5, 2024

  • CVE-2024-1210
    22Monitor

    LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via API

    MediumCVSS 5.3Proof of conceptEPSS 2%

    learndash · learndashFeb 5, 2024

  • LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the materials-content class.

    MediumCVSS 5.4No exploitEPSS 0%

    learndash · learndashFeb 12, 2025

  • LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body class.

    MediumCVSS 5.4No exploitEPSS 0%

    learndash · learndashFeb 12, 2025