Showing 2 vulnerabilities on this page for Rocket LMS

Signals CISA KEV Ransomware Nuclei
RocketSoft vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Rocket LMS 1.1 Persistent Cross-Site Scripting via Support Tickets

Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticated users to inject malicious script code through the title parameter. Attackers can submit support tickets with embedded HTML/JavaScript payloads that execute in the browsers of other users viewing the message history, enabling session hijacking and phishing attacks.

CWE-79May 10, 2026
CVSS5.1v4.0EPSS0.235%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

RocketSoft Rocket LMS Contact Form store cross site scripting

A vulnerability was found in RocketSoft Rocket LMS 1.7. It has been declared as problematic. This vulnerability affects unknown code of the file /contact/store of the component Contact Form. The manipulation of the argument name/subject/message leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-232756.

CWE-79Jun 30, 2023
CVSS3.5v3.1EPSS0.394%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX