Products: 3
    Vulnerabilities: 5
    Known Exploited: 0
    2
    Critical Level Threats
    1
    High Level Threats
    0
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-31283

    Unrestricted Password Reset Causing Email Bombing in Totara LMS

    Last Modified: Apr 29, 2026
    Published: Apr 13, 2026

    CVE-2026-31281

    Totara LMS In‑App Messaging HTML Injection Leading to Cross‑Site Scripting

    Last Modified: Apr 28, 2026
    Published: Apr 13, 2026

    CVE-2026-31282

    Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to reveal the login form. An attacker can chain that with missing rate-limit on the login form to launch a brute force attack. NOTE: this is disputed by the Supplier because (1) local login is enabled/disabled server side (this is not a client side control); (2) there is no evidence SSO login can be bypassed to allow local login; and (3) there is no evidence that local login can be performed when disabled server side.

    Last Modified: May 06, 2026
    Published: Apr 13, 2026

    CVE-2024-3932

    Totara LMS User Selector cross-site request forgery

    Last Modified: Apr 15, 2026
    Published: Apr 18, 2024

    CVE-2024-3931

    Totara LMS User Selector check.php cross site scripting

    Last Modified: Jun 10, 2025
    Published: Apr 18, 2024
    Items Per Page