Masterstudy Lms
Vendor:
First CVE: Mar 7, 2022 · Active for 4 years
15
Total CVEs
More Total CVEs than 92% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Masterstudy Lms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2022
4 years ago
Most Recent CVE
Jun 15, 2026
41 days ago
CVE Severity & Scoring
Masterstudy Lms15 CVEs
27%
33%
40%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (86.7%)
Unknown0 (0.0%)
Required2 (13.3%)
Privileges Required
Low6 (40.0%)
High0 (0.0%)
None9 (60.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0441CRITICAL The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin | Mar 7, 2022 | 9.8 | 92 | NO | YES |
CVE-2024-1512CRITICAL The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms | Feb 17, 2024 | 9.8 | 81 | NO | YES |
CVE-2024-3136CRITICAL The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for | Apr 9, 2024 | 9.8 | 40 | NO | YES |
CVE-2023-4278HIGH The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructo | Sep 11, 2023 | 7.5 | 34 | NO | YES |
CVE-2024-2411CRITICAL The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for una | Mar 29, 2024 | 9.8 | 32 | NO | NO |
CVE-2024-2409CRITICAL The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the | Mar 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2026-40766HIGH Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions. | Jun 15, 2026 | 8.5 | 28 | NO | NO |
CVE-2024-37094CRITICAL Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects MasterStudy LMS: | Nov 1, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-5973HIGH The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionaliti | Jul 22, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-37093HIGH Cross-Site Request Forgery (CSRF) vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Cross Site Request Forgery.This issue affects MasterSt | Jan 2, 2025 | 8.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.7% of CVEs· 97th percentile
Nuclei
3 CVEs
20.0% of CVEs· 98th percentile
ExploitDB
2 CVEs
13.3% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Masterstudy Lms
Top CWEs
Versions
No cataloged versions.