School Management System for Wordpress

School Management System for Wordpress has 23 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2026; 6 are fixed and 17 remain unpatched as of September 2026. Their average CVSS score is 7.2, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 9 high. 2025 was the busiest year with 18 disclosures.

The most common weakness is SQL Injection, behind 7 of the records (30%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type, Missing Authorization.

6 of the records (26%) have a vendor fix, while 17 remain unpatched. The oldest unresolved one dates back to 2017.

13 independent researchers contributed these findings, most of them (3) reported by Bonds.

01234567891026.09.2017Today26.09.20178.8Mojoomla School Management System (Unspecified Version) - Authenticated (Student+) SQL Injection CVSS 8.8 · 26.09.201713.07.20198.8School Management System for Wordpress <= 56.0 - Cross-Site Request Forgery CVSS 8.8 · 13.07.201922.11.20248.8School Management <= 91.5.0 - Authenticated (Student+) Arbitrary File Upload CVSS 8.8 · 22.11.20249.8School Management <= 91.5.0 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 22.11.202406.03.20256.5School Management System for Wordpress <= 92.0.0 - Authenticated (Subscriber+) SQL Injection via 'mj_smgt_show_event_task' CVSS 6.5 · 06.03.20258.8School Management System for Wordpress <= 93.0.0 - Authenticated (Student+) Account Takeover and Privilege Escalation CVSS 8.8 · 06.03.20256.5School Management System for Wordpress <= 92.0.0 - Authenticated (Student+) SQL Injection via 'view-attendance' CVSS 6.5 · 06.03.20255.3School Management System for Wordpress <= 93.0.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion CVSS 5.3 · 06.03.20255.3School Management System for Wordpress <= 93.0.0 - Reflected Cross-Site Scripting CVSS 5.3 · 06.03.202520.05.20256.1School Management <= 92.0.0 - Reflected Cross-Site Scripting CVSS 6.1 · 20.05.20256.5School Management <= 92.0.0 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 20.05.202511.06.20257.5School Management <= 92.0.0 - Unauthenticated SQL Injection CVSS 7.5 · 11.06.202512.06.20258.8School Management <= 93.0.0 - Authenticated (Student+) Local File Inclusion CVSS 8.8 · 12.06.202517.06.20256.3School Management <= 93.2.0 - Authenticated (Support Staff+) Privilege Escalation CVSS 6.3 · 17.06.202518.06.20256.1School Management <= 92.0.0 - Reflected Cross-Site Scripting CVSS 6.1 · 18.06.202517.07.20258.8School Management System for Wordpress <= 93.1.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update CVSS 8.8 · 17.07.202512.08.20259.8School Management <= 1.93.1 (02-07-2025) - Authenticated (Student+) Arbitrary File Upload CVSS 9.8 · 12.08.202515.08.20254.3School Management <= 93.2.0 - Missing Authorization CVSS 4.3 · 15.08.20256.5School Management <= 93.2.0 - Authenticated (Support staff+) SQL Injection CVSS 6.5 · 15.08.20255.3School Management <= 93.1.0 - Unauthenticated Insecure Direct Object Reference CVSS 5.3 · 15.08.20258.8School Management System <= 93.2.0 - Authenticated (Student+) Arbitrary File Upload CVSS 8.8 · 15.08.20257.5School Management System for Wordpress <= 93.2.0 - Unauthenticated SQL Injection CVSS 7.5 · 15.08.202515.08.20265.3School Management <= 93.1.0 - Unauthenticated Insecure Direct Object Reference CVSS 5.3 · 15.08.2026

Strategic Overview

Avg CVSSHigh
7.2/ 10
Patch Coverage26%
Open

17

Fixed

6

Get automatic notifications for all School Management System for Wordpress vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2025-31100

School Management <= 1.93.1 (02-07-2025) - Authenticated (Student+) Arbitrary File Upload

Read the full analysis

Vulnerability Records

23 records
2026-08-15 00:00CVE-2025-15657
5.3
Medium
Tran Nguyen Bao KhanhNo
2025-08-15 14:57CVE-2024-12612
7.5
High
Lucio SáNo
2025-08-15 14:56CVE-2025-6079
8.8
High
FoxyyyNo
2025-08-15 00:00CVE-2025-48108
4.3
Medium
Nguyen Kim SangNo
2025-08-15 00:00CVE-2025-49898
6.5
Medium
Thái AnNo
2025-08-15 00:00CVE-2025-49896
5.3
Medium
Tran Nguyen Bao KhanhNo
2025-08-12 00:00CVE-2025-31100
9.8
Critical
BondsNo
2025-07-17 00:00CVE-2025-3740
8.8
High
Thái AnYes
2025-06-18 00:00CVE-2025-47574
6.1
Medium
BondsNo
2025-06-17 00:00CVE-2025-15656
6.3
Medium
Thái AnNo
Showing 1–10 of 23 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C