Known Vulnerabilities for products from Formalms
Listed below are 14 of the newest known vulnerabilities associated with the vendor "Formalms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-42925 json | There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of ... | 8.8 - HIGH | 2022-10-31 | 2022-11-01 |
| CVE-2022-42924 json | Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerabi... | 6.5 - MEDIUM | 2022-10-31 | 2022-11-01 |
| CVE-2022-42923 json | Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerabi... | 8.8 - HIGH | 2022-10-31 | 2022-11-01 |
| CVE-2022-41681 json | There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of ... | 8.8 - HIGH | 2022-10-31 | 2022-11-01 |
| CVE-2022-41680 json | Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerabi... | 6.5 - MEDIUM | 2022-10-31 | 2022-11-01 |
| CVE-2022-41679 json | Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker... | 6.1 - MEDIUM | 2022-10-31 | 2022-11-01 |
| CVE-2022-27104 json | An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3. | 9.8 - CRITICAL | 2022-04-19 | 2022-04-27 |
| CVE-2021-43136 json | An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a va... | 9.8 - CRITICAL | 2021-11-10 | 2022-07-12 |
| CVE-2020-26802 json | forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=savein... | 8.8 - HIGH | 2020-10-08 | 2020-10-15 |
| CVE-2019-5112 json | Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php U... | 8.8 - HIGH | 2019-12-03 | 2022-07-17 |
| CVE-2019-5111 json | Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php U... | 8.8 - HIGH | 2019-12-03 | 2022-07-17 |
| CVE-2019-5110 json | Exploitable SQL injection vulnerabilities exist in the authenticated portion of Forma LMS 2.2.1. Specially crafted web reques... | 8.8 - HIGH | 2019-12-03 | 2022-07-17 |
| CVE-2019-5109 json | Exploitable SQL injection vulnerabilities exists in the authenticated portion of Forma LMS 2.2.1. Specially crafted web reque... | 8.8 - HIGH | 2019-12-03 | 2022-07-17 |
| CVE-2014-5257 json | Multiple cross-site scripting (XSS) vulnerabilities in Forma Lms before 1.2.1 p01 allow remote attackers to inject arbitrary ... | Not Provided | 2014-11-06 | 2026-05-06 |
Known software with vulnerabilities from Formalms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Formalms | Formalms | 1.0 |