Vulnerability index

Browse CVEs

60 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tutor Lms MEDIUM 5.3
CVE-2025-11564

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil…

Fix: 3.9.0+
Fix from $1,600 2025-10-25
Droip HIGH 8.8
CVE-2025-5835

The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability check on the droip_post_apis…

Fix: after 2.2.0
Fix from $1,950 2025-07-25
Droip HIGH 8.8
CVE-2025-5831

The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_google_font_offline() function…

Fix: after 2.2.0
Fix from $1,950 2025-07-25
Wp Crowdfunding MEDIUM 5.3
CVE-2025-1508

The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action i…

Fix: after 2.1.13
Fix from $1,600 2025-03-12
Qubely MEDIUM 6.5
CVE-2024-13228

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8…

Fix: 1.8.14+
Fix from $1,600 2025-03-11
Qubely MEDIUM 5.4
CVE-2025-26767

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This is…

Fix: 1.8.13+
Fix from $1,600 2025-02-16
Qubely MEDIUM 5.4
CVE-2024-9601

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ and 'UniqueID' parameter in…

Fix: 1.8.13+
Fix from $1,600 2025-02-14
Wp Crowdfunding HIGH 8.8
CVE-2023-41870

Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

Fix: 2.1.6+
Fix from $1,950 2024-12-13
Wp Crowdfunding MEDIUM 5.4
CVE-2024-11910

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search block in all versions up to, and…

Fix: 2.1.13+
Fix from $1,600 2024-12-13
Tutor Lms Elementor Addons HIGH 8.8
CVE-2024-53816

Missing Authorization vulnerability in Themeum Tutor LMS Elementor Addons tutor-lms-elementor-addons.This issue affects Tutor LMS Elementor Addons: f…

Fix: 2.1.6+
Fix from $1,950 2024-12-09
Tutor Lms HIGH 7.5
CVE-2024-10400EPSS 82%

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due t…

Fix: after 2.7.6
Fix from $1,950 2024-11-21
Tutor Lms MEDIUM 5.3
CVE-2024-10393

The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing che…

Fix: after 2.7.6
Fix from $1,600 2024-11-21
Tutor Lms HIGH 8.8
CVE-2024-43142

Missing Authorization vulnerability in Themeum Tutor LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects T…

Fix: 2.7.4+
Fix from $1,950 2024-11-01
Wp Crowdfunding MEDIUM 5.4
CVE-2024-10117

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcf_donate shortcode in all versions up to, a…

Fix: 2.1.12+
Fix from $1,600 2024-10-26
Tutor Lms HIGH 7.1
CVE-2024-5784

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple…

Fix: 2.7.3+
Fix from $1,950 2024-08-30
Droip HIGH 7.5
CVE-2024-43955

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows File Manipulation.This issue aff…

Fix: after 1.1.1
Fix from $1,950 2024-08-29
Droip MEDIUM 6.3
CVE-2024-43954

Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Droip: from…

Fix: after 1.1.1
Fix from $1,600 2024-08-29
Tutor Lms HIGH 8.8
CVE-2024-39645

Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.

Fix: 2.7.3+
Fix from $1,950 2024-08-26
Tutor Lms Elementor Addons MEDIUM 5.4
CVE-2024-5576

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'course_carousel_skin' attribute within the …

Fix: 2.1.5+
Fix from $1,600 2024-08-20
Tutor Lms HIGH 7.2
CVE-2024-43282

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS:…

Fix: 2.7.3+
Fix from $1,950 2024-08-18
Tutor Lms MEDIUM 5.4
CVE-2024-43231

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This…

Fix: 2.7.4+
Fix from $1,600 2024-08-12
Tutor Lms Migration Tool MEDIUM 5.3
CVE-2024-1798

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the tutor_lp_ex…

Fix: after 2.2.2
Fix from $1,600 2024-07-27
Tutor Lms HIGH 7.2
CVE-2024-37266

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows Path Traversal.This issue af…

Fix: 2.7.2+
Fix from $1,950 2024-07-09
Tutor Lms HIGH 7.2
CVE-2024-37256

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS:…

Fix: 2.7.2+
Fix from $1,950 2024-07-09
Tutor Lms HIGH 8.8
CVE-2023-25799

Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.

Fix: 2.1.9+
Fix from $1,950 2024-06-11
Tutor Lms HIGH 7.2
CVE-2024-4902

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘course_id’ parameter in …

Fix: 2.7.2+
Fix from $1,950 2024-06-07
Tutor Lms HIGH 8.8
CVE-2024-4352

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability c…

Fix: 2.7.1+
Fix from $1,950 2024-05-16
Tutor Lms HIGH 8.8
CVE-2024-4351

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability c…

Fix: 2.7.1+
Fix from $1,950 2024-05-16
Tutor Lms HIGH 8.2
CVE-2024-4222

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability c…

Fix: 2.7.1+
Fix from $1,950 2024-05-16
Tutor Lms CRITICAL 9.8
CVE-2024-4223

The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check…

Fix: 2.7.1+
Fix from $2,300 2024-05-16