Formalms
Vendor:
First CVE: Nov 6, 2014 · Active for 11 years
17
Total CVEs
More Total CVEs than 94% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Formalms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 6, 2014
11 years ago
Most Recent CVE
Feb 19, 2026
158 days ago
CVE Severity & Scoring
Formalms17 CVEs
41%
47%
12%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (94.1%)
Unknown1 (5.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (94.1%)
High0 (0.0%)
Unknown1 (5.9%)
User Interaction
None13 (76.5%)
Unknown1 (5.9%)
Required3 (17.6%)
Privileges Required
Low10 (58.8%)
High0 (0.0%)
None6 (35.3%)
Unknown1 (5.9%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43136CRITICAL An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform. | Nov 10, 2021 | 9.8 | 50 | NO | YES |
CVE-2022-27104CRITICAL An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3. | Apr 19, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-42923HIGH Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the ro | Oct 31, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-42925HIGH There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege escalate in order to upload a Zip | Oct 31, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-41681HIGH There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege escalate in order to upload a Zip | Oct 31, 2022 | 8.8 | 27 | NO | NO |
CVE-2019-5112HIGH Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_status was confirmed to suffer | Dec 3, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-5111HIGH Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_cat was confirmed to suffer fro | Dec 3, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-5110HIGH Exploitable SQL injection vulnerabilities exist in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause SQL injections. An attacker can send a web | Dec 3, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-5109HIGH Exploitable SQL injection vulnerabilities exists in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause SQL injections. An attacker can send a we | Dec 3, 2019 | 8.8 | 26 | NO | NO |
CVE-2022-42924MEDIUM Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the ro | Oct 31, 2022 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.9% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Formalms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.3.0.2 | 1 | 8.8 | 0.7% | 0 | 0 |
| 2.2.1 | 4 | 8.8 | 1.3% | 0 | 0 |