Atutor is an open-source learning management system with a small but prominent footprint in the educational software landscape, supported by a focused product portfolio including the core platform, content management, collaboration, and accessibility-checking tools. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, reflecting the platform's web-facing role and exposure to a broad user base of institutions and learners. The exposure recurs through a consistent pattern of web-application weaknesses: cross-site scripting, SQL injection, cross-site request forgery, path traversal, and unrestricted file uploads—flaws endemic to dynamic web applications with insufficient input sanitization and access controls. Defenders deploying this platform should prioritize patching and apply strict input validation, file-upload restrictions, and CSRF protections across all user-facing interfaces; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Atutor over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2555CRITICAL SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends | Apr 13, 2017 | 9.8 | 88 | NO | YES |
CVE-2019-12169HIGH ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_impo | Jun 3, 2019 | 8.8 | 77 | NO | YES |
CVE-2017-1000002CRITICAL ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 | Jul 17, 2017 | 9.8 | 59 | NO | YES |
CVE-2019-11446HIGH An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files section in the File Manager fiel | Apr 22, 2019 | 8.8 | 41 | NO | YES |
CVE-2016-2539HIGH Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload | Feb 7, 2017 | 8.8 | 40 | NO | YES |
CVE-2023-27008MEDIUM A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to inject arbitrary web script or HTML via t | Mar 28, 2023 | 6.1 | 34 | NO | YES |
CVE-2017-1000004CRITICAL ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course Alumni, Course Enrolment, Group | Jul 17, 2017 | 9.8 | 33 | NO | NO |
CVE-2012-5167HIGH Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field parameter to course_category/index | Oct 22, 2012 | 7.5 | 33 | NO | YES |
CVE-2014-9753CRITICAL confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter. | Feb 11, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-12170HIGH ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote command execution. An attacker | May 17, 2019 | 8.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Atutor.
Media articles that mention a CVE ID that affects a product developed by Atutor — matched by CVE ID, not by vendor name.