vciy

CVEs we hold for Masteriyo

Records whose assigning authority named Masteriyo as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-82851Masteriyo LMS 1.14.0 - 3.4.0 - Instructor+ Arbitrary Post Disclosure via IDORUnknown Masteriyo LMS
CVE-2026-82848Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment DisclosureUnknown Masteriyo LMS
CVE-2026-82847Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course HighlightsUnknown Masteriyo LMS
CVE-2026-82846Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom FieldsUnknown Masteriyo LMS
CVE-2026-82845Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object InjectionUnknown Masteriyo LMS
CVE-2026-8279Masteriyo LMS <= 2.2.0 - Missing Authorization to Unauthenticated Arbitrary Course Progress DeletionMasteriyo LMS – LMS Course Builder, Quizzes & Certificates
CVE-2026-73996WordPress Masteriyo - LMS plugin <= 2.3.2 - Arbitrary File Upload vulnerabilityMasteriyo - LMS
CVE-2026-65463WordPress Masteriyo - LMS plugin <= 2.3.1 - Insecure Direct Object References (IDOR) vulnerabilityMasteriyo - LMS
CVE-2026-62132WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerabilityMasteriyo - LMS
CVE-2026-62107WordPress Masteriyo - LMS plugin <= 3.4.0 - PHP Object Injection vulnerabilityMasteriyo - LMS
CVE-2026-59513WordPress Masteriyo - LMS plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerabilityMasteriyo - LMS
CVE-2026-5167Masteriyo LMS <= 2.1.7 - Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook EndpointMasteriyo LMS – Online Course Builder for eLearning, LMS &…
CVE-2026-4484Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to AdministratorMasteriyo LMS – Online Course Builder for eLearning, LMS &…
CVE-2026-19712Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz DescriptionUnknown Masteriyo LMS
CVE-2026-13332Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Service)Unknown Masteriyo LMS
CVE-2026-11773Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement ModificationMasteriyo LMS – LMS Course Builder, Quizzes & Certificates
CVE-2026-10824Masteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and DeletionUnknown Masteriyo LMS
CVE-2025-64270WordPress Masteriyo - LMS plugin <= 2.0.3 - Sensitive Data Exposure vulnerabilityMasteriyo - LMS
CVE-2025-54699WordPress Masteriyo - LMS Plugin plugin <= 1.18.3 - Cross Site Scripting (XSS) VulnerabilityMasteriyo - LMS
CVE-2024-43239WordPress Masteriyo LMS plugin <= 1.11.4 - Insecure Direct Object Reference (IDOR) vulnerabilityMasteriyo - LMS
CVE-2024-43159WordPress Masteriyo LMS plugin <= 1.11.6 - Broken Access Control vulnerabilityMasteriyo - LMS
CVE-2024-43158WordPress Masteriyo LMS plugin <= 1.11.4 - Broken Access Control vulnerabilityMasteriyo - LMS
CVE-2024-33939WordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerabilityMasteriyo - LMS
CVE-2024-24882WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerabilityMasteriyo - LMS
CVE-2024-10008Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Missing…Masteriyo LMS – Online Course Builder for eLearning, LMS &…
CVE-2024-10000Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Stored…Masteriyo LMS – Online Course Builder for eLearning, LMS &…

26 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.