Tutor Lms

Vendor:

First CVE: Feb 4, 2020 · Active for 6 years

57
Total CVEs
More Total CVEs than 98% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tutor Lms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2020
6 years ago
Most Recent CVE
Jul 13, 2026
11 days ago

CVE Severity & Scoring

Tutor Lms57 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network57 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low57 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None41 (71.9%)
Unknown0 (0.0%)
Required16 (28.1%)
Privileges Required
Low31 (54.4%)
High10 (17.5%)
None16 (28.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the
Nov 21, 20247.577NOYES
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such
Feb 4, 20206.542NOYES
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and includi
Mar 13, 20248.836NOYES
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects
Jan 22, 20268.129NONO
The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross
Feb 6, 20236.129NOYES
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all v
May 16, 20249.828NONO
Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and el
Apr 5, 20218.828NONO
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects
Jul 13, 20266.527NONO
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' func
May 16, 20248.827NONO
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a
Nov 3, 20239.826NONO

Exploit Exposure

Signals from CVEs in this product scope (57 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
7.0% of CVEs· 97th percentile
ExploitDB
1 CVE
1.8% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (57 CVEs).

Media Mentions

Signals from CVEs in this product scope (57 CVEs).

Top CNAs Publishing CVEs For Tutor Lms

Top CWEs

Versions

No cataloged versions.