← Back

Sensei Lms

sensei_lms

Vendor: Automattic • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Automattic
1Sensei Lms
Nov 13, 2025
May 15, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page
1Automattic
1Sensei Lms
Sep 30, 2025
Feb 4, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.
1Automattic
1Sensei Lms
Oct 7, 2024
Sep 4, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.
1Automattic
1Sensei Lms
Apr 28, 2026
Feb 12, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS – Online C...Show more
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS – Online Courses, Quizzes, & Learning: from n/a through 4.17.0.Show less
1Automattic
1Sensei Lms
Nov 21, 2024
Aug 29, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conver...Show more
The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the teacher and studentShow less
1Automattic
1Sensei Lms
Nov 21, 2024
Aug 29, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers