CVE-2026-39405
Severity CVSS v4.0:
CRITICAL
Type:
CWE-22
Path Traversal
Publication date:
20/05/2026
Last modified:
21/05/2026
Description
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to write files outside the intended directory. This issue has been resolved in version 2.50.1.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL



