Kodezen's vulnerability profile centers on its Academy LMS product, a learning-management system where disclosed issues cluster around authentication and authorization handling, including missing authorization checks, authorization bypass through user-controlled parameters, and improper privilege management. The exposure also encompasses sensitive information disclosure, reflecting the access-control and data-confidentiality demands of educational platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kodezen over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1505HIGH The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This i | Mar 13, 2024 | 8.8 | 25 | NO | NO |
CVE-2026-9341MEDIUM The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, | Jul 14, 2026 | 4.3 | 24 | NO | NO |
CVE-2024-38701HIGH Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4. | Jul 22, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-32714HIGH Missing Authorization vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.16. | Jun 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-33912HIGH Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16. | May 6, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-35171MEDIUM Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.25. | May 14, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kodezen.
Media articles that mention a CVE ID that affects a product developed by Kodezen — matched by CVE ID, not by vendor name.