CVE-2025-62778
Severity CVSS v4.0:
LOW
Type:
CWE-425
Direct Request ('Forced Browsing')
Publication date:
27/10/2025
Last modified:
03/11/2025
Description
Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to access the Quiz Form if they had the URL.
Impact
Base Score 4.0
1.30
Severity 4.0
LOW
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:* | 2.0.0 (including) | 2.39.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



