VendorsThemeumtutor_lmsany version
Vulnerabilities

Themeum Tutor LMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2024-10393
Tutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User Registration
Published 2024-11-21 · Analyzed
5.3EPSS 0.006
CVE-2025-11564
Tutor LMS – eLearning and online course solution <= 3.8.3 - Missing Authorization to Unauthenticated Payment Status Update
Published 2025-10-25 · Analyzed
5.3EPSS 0.003
CVE-2021-24740
Tutor LMS < 1.9.9 - Multiple Admin+ Stored Cross-Site Scripting
Published 2021-10-18 · Modified
4.8EPSS 0.006
CVE-2022-2563
Tutor LMS < 2.0.10 - Admin+ Stored Cross-Site Scripting
Published 2022-10-17 · Modified
4.8EPSS 0.006
CVE-2024-1133
Tutor LMS <= 2.6.0 - Missing Authorization
Published 2024-02-20 · Modified
4.3EPSS 0.004
CVE-2024-5438
Tutor LMS – eLearning and online course solution <= 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt Deletion
Published 2024-06-07 · Modified
4.3EPSS 0.003
CVE-2023-2919
Tutor LMS <= 2.7.4 - Cross-Site Request Forgery via 'addon_enable_disable'
Published 2024-09-10 · Analyzed
4.3EPSS 0.002
CVE-2024-1503
Tutor LMS – eLearning and online course solution <= 2.6.1 - Cross-Site Request Forgery to Plugin Deactivation and Data Erase
Published 2024-03-12 · Modified
4.3EPSS 0.002
CVE-2025-6680
Tutor LMS <= 3.8.3 - Missing Authorization to Sensitive Information Exposure
Published 2025-10-25 · Analyzed
4.3EPSS 0.002
← Prev2 / 2