RocketSoft Vulnerabilities and Affected Products
Vulnerabilities associated with Rocket LMS.
Products
Clear product- Rocket LMS2 vulnerabilities
- rocket_lms1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-47907MEDIUM | Rocket LMS 1.1 Persistent Cross-Site Scripting via Support TicketsRocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticated users to inject malicious script code through the title parameter. Attackers can submit support tickets with embedded HTML/JavaScript payloads that execute in the browsers of other users viewing the message history, enabling session hijacking and phishing attacks. CWE-79May 10, 2026 | CVSS5.1v4.0 | EPSS0.235% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
RocketSoft Rocket LMS Contact Form store cross site scriptingA vulnerability was found in RocketSoft Rocket LMS 1.7. It has been declared as problematic. This vulnerability affects unknown code of the file /contact/store of the component Contact Form. The manipulation of the argument name/subject/message leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-232756. CWE-79Jun 30, 2023 | CVSS3.5v3.1 | EPSS0.394% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |