Known vulnerabilities in the Lifterlms plugin
14 security advisories have been published for the Lifterlms plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Lifterlms - Broken Access Control (CVE-2026-14231) MEDIUM
- Lifterlms - Security Vulnerability (CVE-2026-14207) MEDIUM
- LifterLMS - SQL Injection (CVE-2026-5207) MEDIUM
- Lifterlms - Privilege Escalation (CVE-2025-11923) HIGH
- Lifterlms - Cross-Site Scripting (XSS) (CVE-2024-13619) MEDIUM
- Lifterlms - Broken Access Control (CVE-2025-2290) MEDIUM
- Lifterlms - Broken Access Control (CVE-2024-12596) MEDIUM
- Lifterlms - SQL Injection (CVE-2024-7349) HIGH
- Lifterlms - SQL Injection (CVE-2024-4743) CRITICAL
- Lifterlms - Broken Access Control (CVE-2024-0377) MEDIUM
- Lifterlms - Path Traversal (CVE-2023-6160) LOW
- Lifterlms - Cross-Site Scripting (XSS) (CVE-2022-1250) MEDIUM
- Lifterlms - Security Vulnerability (CVE-2021-24562) HIGH
- Lifterlms - Cross-Site Scripting (XSS) (CVE-2021-24308) MEDIUM