Vulnerabilities (CVE)

Filtered by vendor Themeum Subscribe
Filtered by product Tutor Lms
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24183 1 Themeum 1 Tutor Lms 2021-04-09 4.0 MEDIUM 6.5 MEDIUM
The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.
CVE-2021-24185 1 Themeum 1 Tutor Lms 2021-04-09 4.0 MEDIUM 6.5 MEDIUM
The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.