CVE-2026-39385EPSS p28.8%
CVE-2026-39385CVE-2026-39385
Description
Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.
Scoring
| EPSS | 0.37% probability of exploitation · percentile 28.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-22 |