Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Atutor

First CVE: Feb 19, 2008Active for: 18 yearsTotal CVEs: 39
46.9
VTI Score
High

Atutor is an open-source learning management system with a small but prominent footprint in the educational software landscape, supported by a focused product portfolio including the core platform, content management, collaboration, and accessibility-checking tools. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, reflecting the platform's web-facing role and exposure to a broad user base of institutions and learners. The exposure recurs through a consistent pattern of web-application weaknesses: cross-site scripting, SQL injection, cross-site request forgery, path traversal, and unrestricted file uploads—flaws endemic to dynamic web applications with insufficient input sanitization and access controls. Defenders deploying this platform should prioritize patching and apply strict input validation, file-upload restrictions, and CSRF protections across all user-facing interfaces; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
39
Total CVEs
More Total CVEs than 98% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Atutor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 19, 2008
18 years ago
Most Recent CVE
Mar 28, 2023
1,214 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-2555CRITICAL
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends
Apr 13, 20179.888NOYES
CVE-2019-12169HIGH
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_impo
Jun 3, 20198.877NOYES
CVE-2017-1000002CRITICAL
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1
Jul 17, 20179.859NOYES
CVE-2019-11446HIGH
An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files section in the File Manager fiel
Apr 22, 20198.841NOYES
CVE-2016-2539HIGH
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload
Feb 7, 20178.840NOYES
CVE-2023-27008MEDIUM
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to inject arbitrary web script or HTML via t
Mar 28, 20236.134NOYES
CVE-2017-1000004CRITICAL
ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course Alumni, Course Enrolment, Group
Jul 17, 20179.833NONO
CVE-2012-5167HIGH
Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field parameter to course_category/index
Oct 22, 20127.533NOYES
CVE-2014-9753CRITICAL
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter.
Feb 11, 20209.831NONO
CVE-2019-12170HIGH
ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote command execution. An attacker
May 17, 20198.831NONO
View all 39 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products39 CVEs
51%
28%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (53.8%)
Unknown18 (46.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (53.8%)
High0 (0.0%)
Unknown18 (46.2%)
User Interaction
None11 (28.2%)
Unknown18 (46.2%)
Required10 (25.6%)
Privileges Required
Low5 (12.8%)
High0 (0.0%)
None16 (41.0%)
Unknown18 (46.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (39 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
7.7% of CVEs· 98th percentile
Nuclei
1 CVE
2.6% of CVEs· 95th percentile
ExploitDB
9 CVEs
23.1% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Atutor.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Atutor — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Atutor's Products

View all 1 CNAs →

Top CWEs