Aggregates CVE and security vulnerability intelligence across all beakon-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk sql injection and vendor risk cross-site scripting, with potential vendor impact session compromise and vendor impact data exposure across vendor surface production workloads use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-55373 | Incorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to escalate privileges and execute commands with Administrator rights. | [email protected] | 5.3 | 0.07% | 2025-09-02 | 2025-09-11 |
| CVE-2025-55372 | An arbitrary file upload vulnerability in Beakon Application before v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. | [email protected] | 5.3 | 0.17% | 2025-09-02 | 2025-09-11 |
| CVE-2025-46102 | Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version V.5.4.3 allows a remote attacker to obtain sensitive information via the URL parameter | [email protected] | 5.4 | 0.16% | 2025-07-17 | 2025-10-14 |
| CVE-2025-46101 | SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain sensitive information via the ks parameter in json_scorm.php file | [email protected] | 9.8 | 0.61% | 2025-06-23 | 2025-10-16 |