Tutor Lms
Vendor:
First CVE: Feb 4, 2020 · Active for 6 years
57
Total CVEs
More Total CVEs than 98% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tutor Lms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2020
6 years ago
Most Recent CVE
Jul 13, 2026
11 days ago
CVE Severity & Scoring
Tutor Lms57 CVEs
60%
33%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network57 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low57 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None41 (71.9%)
Unknown0 (0.0%)
Required16 (28.1%)
Privileges Required
Low31 (54.4%)
High10 (17.5%)
None16 (28.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-10400HIGH The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the | Nov 21, 2024 | 7.5 | 77 | NO | YES |
CVE-2020-8615MEDIUM A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such | Feb 4, 2020 | 6.5 | 42 | NO | YES |
CVE-2024-1751HIGH The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and includi | Mar 13, 2024 | 8.8 | 36 | NO | YES |
CVE-2025-47555HIGH Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects | Jan 22, 2026 | 8.1 | 29 | NO | NO |
CVE-2023-0236MEDIUM The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross | Feb 6, 2023 | 6.1 | 29 | NO | YES |
CVE-2024-4223CRITICAL The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all v | May 16, 2024 | 9.8 | 28 | NO | NO |
CVE-2021-24184HIGH Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and el | Apr 5, 2021 | 8.8 | 28 | NO | NO |
CVE-2026-57694MEDIUM Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects | Jul 13, 2026 | 6.5 | 27 | NO | NO |
CVE-2024-4351HIGH The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' func | May 16, 2024 | 8.8 | 27 | NO | NO |
CVE-2023-25700CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a | Nov 3, 2023 | 9.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (57 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
7.0% of CVEs· 97th percentile
ExploitDB
1 CVE
1.8% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (57 CVEs).
Media Mentions
Signals from CVEs in this product scope (57 CVEs).
Top CNAs Publishing CVEs For Tutor Lms
Top CWEs
Versions
No cataloged versions.