Known Vulnerabilities for Formalms by Formalms
Listed below are 10 of the newest known vulnerabilities associated with "Formalms" by "Formalms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-42925 json | There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of ... | 8.8 - HIGH | 2022-10-31 | 2022-11-01 |
| CVE-2022-42924 json | Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerabi... | 6.5 - MEDIUM | 2022-10-31 | 2022-11-01 |
| CVE-2022-42923 json | Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerabi... | 8.8 - HIGH | 2022-10-31 | 2022-11-01 |
| CVE-2022-41681 json | There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of ... | 8.8 - HIGH | 2022-10-31 | 2022-11-01 |
| CVE-2022-41680 json | Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerabi... | 6.5 - MEDIUM | 2022-10-31 | 2022-11-01 |
| CVE-2022-41679 json | Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker... | 6.1 - MEDIUM | 2022-10-31 | 2022-11-01 |
| CVE-2022-27104 json | An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3. | 9.8 - CRITICAL | 2022-04-19 | 2022-04-27 |
| CVE-2021-43136 json | An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a va... | 9.8 - CRITICAL | 2021-11-10 | 2022-07-12 |
| CVE-2020-26802 json | forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=savein... | 8.8 - HIGH | 2020-10-08 | 2020-10-15 |
| CVE-2019-5112 json | Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php U... | 8.8 - HIGH | 2019-12-03 | 2022-07-17 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Formalms | Formalms | 2.3.0.2 | |||
| Application | Formalms | Formalms | 2.3 | |||
| Application | Formalms | Formalms | 2.2.1 | |||
| Application | Formalms | Formalms | 2.1 | |||
| Application | Formalms | Formalms | 2.0 | |||
| Application | Formalms | Formalms | 1.4.3 | |||
| Application | Formalms | Formalms | 1.4.2 | |||
| Application | Formalms | Formalms | 1.4.1 | |||
| Application | Formalms | Formalms | 1.4 | |||
| Application | Formalms | Formalms | 1.4 | |||
| Application | Formalms | Formalms | 1.3 | |||
| Application | Formalms | Formalms | 1.3 | |||
| Application | Formalms | Formalms | 1.3 | |||
| Application | Formalms | Formalms | 1.3 | |||
| Application | Formalms | Formalms | 1.3 | |||
| Application | Formalms | Formalms | 1.2.1 | |||
| Application | Formalms | Formalms | 1.2.1 | |||
| Application | Formalms | Formalms | 1.2.1 | |||
| Application | Formalms | Formalms | 1.2 | |||
| Application | Formalms | Formalms | 1.2 |