Masteriyo is a learning management and course delivery platform with a focused vulnerability footprint concentrated in its core product, where the observed weakness classes center on authorization and access-control lapses alongside input-handling issues such as cross-site scripting. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Masteriyo over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43239HIGH Authorization Bypass Through User-Controlled Key vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11. | Aug 18, 2024 | 8.1 | 23 | NO | NO |
CVE-2024-10000MEDIUM The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all | Oct 29, 2024 | 5.4 | 21 | NO | NO |
CVE-2024-43158HIGH Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4. | Nov 1, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-10008MEDIUM The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization chec | Oct 29, 2024 | 6.5 | 17 | NO | NO |
CVE-2024-43159MEDIUM Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.6. | Nov 1, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Masteriyo.
Media articles that mention a CVE ID that affects a product developed by Masteriyo — matched by CVE ID, not by vendor name.