CVE-2026-39405
NONE—CVSS v3
—CVSS v2
0.05%
EPSS (exploit probability)
CWE-22CWE
Description
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to write files outside the intended directory. This issue has been resolved in version 2.50.1.
Affected routers (0)
No routers currently mapped to this CVE in our database.