Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
themeum tutor lms vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-25799
Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a up to and including 2.1.8.
4.3
CVSSv3
CVE-2024-5438
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.1 via the 'attempt_delete' function due to missing validation on a user controlled key. This makes...
Themeum Tutor Lms
NA
CVE-2024-29913
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS Elementor Addons allows Stored XSS.This issue affects Tutor LMS Elementor Addons: from n/a up to and including 2.1.3.
4.8
CVSSv3
CVE-2023-49829
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS – eLearning and online course solution allows Stored XSS.This issue affects Tutor LMS – eLearning and online course solution: from n/a up ...
Themeum Tutor Lms
8.8
CVSSv3
CVE-2023-25800
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a up to and including 2.2.0.
Themeum Tutor Lms
8.8
CVSSv3
CVE-2023-25990
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a up to and including 2.1.10.
Themeum Tutor Lms
9.8
CVSSv3
CVE-2023-25700
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a up to and including 2.1.10.
Themeum Tutor Lms
5.4
CVSSv3
CVE-2023-4805
The Tutor LMS WordPress plugin prior to 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Themeum Tutor Lms
7.5
CVSSv3
CVE-2023-3133
The Tutor LMS WordPress plugin prior to 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated malicious users to access information from Lessons that should not be publicly available.
Themeum Tutor Lms
6.1
CVSSv3
CVE-2023-0236
The Tutor LMS WordPress plugin prior to 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Themeum Tutor Lms
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4541
CVE-2024-3080
CVE-2024-4787
log injection
CVE-2024-5967
inject
CVE-2024-30078
CVE-2024-5899
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »