---
id: CVE-2025-67734
title: >-
  Frappe Learning Management System (LMS) is a learning system that helps users
  structure their content
summary: >-
  Frappe Learning Management System (LMS) is a learning system that helps users
  structure their content. Versions prior to 2.42.0 allowed authenticated
  attackers to enter JavaScript through the Company Website field of the Job
  Form, exposi…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: frappe
product: learning
affected:
  - 'learning >= 2.0.0, < 2.42.0'
patched:
  - learning 2.42.0
published: '2025-12-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67734'
references:
  - url: >-
      https://github.com/frappe/lms/commit/ca849da81558066d7614b9b6234004ff59c90632
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/lms/security/advisories/GHSA-c495-qg4v-5vr7'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00168
epssPercentile: 0.0555
ingestedAt: '2026-10-07T20:46:46.909Z'
---

## Overview

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated attackers to enter JavaScript through the Company Website field of the Job Form, exposing users to an XSS attack. The script could then be executed in the browsers of users who opened the malicious job posting. This issue is fixed in version 2.42.0.

## Affected

- `learning >= 2.0.0, < 2.42.0`

## Remediation

Upgrade past the affected range:

- `learning 2.42.0`
