CVE-2025-62778Medium· 5.3▾ SunlitFrappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to access the Quiz Form if they had the URL.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to access the Quiz Form if they had the URL.
learning >= 2.0.0, < 2.39.2Upgrade past the affected range:
learning 2.39.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62158Medium· 5.3Frappe Learning is a learning system that helps users structure their content
CVE-2025-62779Medium· 5.4Frappe Learning is a learning system that helps users structure their content
CVE-2025-67734Medium· 5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content
CVE-2025-67730Medium· 5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content
CVE-2025-66581Medium· 6.5Frappe Learning Management System (LMS) is a learning system that helps users structure their content
CVE-2025-10655High· 8.8SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0.