
CVE-2026-45140
Disclosure pack and PoC script for CVE-2026-45140, an unauthenticated path traversal and RCE in Chamilo LMS CStudio upload, with a loopback Docker…

Disclosure pack and PoC script for CVE-2026-45140, an unauthenticated path traversal and RCE in Chamilo LMS CStudio upload, with a loopback Docker…

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

Unauthenticated SSRF in the Chamilo LMS PENS plugin — CVE-2026-34160 / CVSS 8.6

Advisory detailing an authenticated HTML injection vulnerability in Totara LMS affecting versions before 19.1.5, enabling session hijacking and…

Technical write-up of CVE-2026-26717, an HMAC timing attack in OpenFUN Richie LMS webhook authentication, including vulnerable code, impact, and fix…

An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout…

A public disclourse of CVE-2025-67730 in Frape lms By dharan ragunathan

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG…

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG…

Proof-of-concept exploit for CVE-2024-10400, a time-based blind SQL injection in Tutor LMS WordPress plugin, allowing unauthenticated attackers to…

Authenticated Privilege Escalation to Admin exploiting Uncanny Groups for LearnDash.

Academy LMS <= 5.10 CSRF

LearnDash LMS < 4.10.3 - Sensitive Information Exposure

PoC for CVE-2024-1512 in MasterStudy LMS WordPress Plugin.

Proof-of-concept for reflected cross-site scripting in Academy LMS versions before 5.9.1, triggered via the search?query parameter to execute…