Frappe LMS Enrollment Bypass Vulnerability in Paid Courses

Vulnerability

An enrollment bypass vulnerability has been identified in Frappe LMS versions through 2.51.0. This issue allows users to circumvent payment validation for courses by using unrelated batches. The vulnerability has been addressed in version 2.52.0, where enrollment now requires that the batch is linked to the course.

Impact

Exploitation of this vulnerability allows users to bypass payment validation for courses, potentially leading to unauthorized access to paid course materials.

Remediation

Users can upgrade to Frappe LMS version 2.52.0 or later to address this vulnerability.

Added: Jul 20, 2026, 8:54 PM
Updated: Jul 20, 2026, 8:54 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
5.4
remediation
7.7
relevance
9.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.