---
id: CVE-2025-67730
title: >-
  Frappe Learning Management System (LMS) is a learning system that helps users
  structure their content
summary: >-
  Frappe Learning Management System (LMS) is a learning system that helps users
  structure their content. Versions prior to 2.42.0 allow authenticated users to
  add malicious HTML and JavaScript through description fields in the Job,
  Course …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: frappe
product: learning
affected:
  - 'learning >= 2.0.0, < 2.42.0'
patched:
  - learning 2.42.0
published: '2025-12-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67730'
references:
  - url: >-
      https://github.com/frappe/lms/commit/0877e32e1bfe64831b875707241de1c449cda45c
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/lms/security/advisories/GHSA-jjc4-j3hw-33h2'
    label: security-advisories@github.com
tags:
  - nvd
  - exploit-available
epss: 0.00172
epssPercentile: 0.05971
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Dharan10/CVE-2025-67730'
  checkedAt: '2026-10-07T20:47:22.829Z'
exploitAvailable: true
ingestedAt: '2026-10-07T20:46:46.897Z'
---

## Overview

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated users to add malicious HTML and JavaScript through description fields in the Job, Course and Batch forms. This issue is fixed in version 2.42.0.

## Affected

- `learning >= 2.0.0, < 2.42.0`

## Remediation

Upgrade past the affected range:

- `learning 2.42.0`
