Vulnerability index

Browse CVEs

60 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tutor Lms MEDIUM 6.5
CVE-2024-4318

The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions up to, and including, 2.7.0 …

Fix: 2.7.1+
Fix from $1,600 2024-05-16
Tutor Lms MEDIUM 6.5
CVE-2024-4279

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Delet…

Fix: 2.7.1+
Fix from $1,600 2024-05-16
Tutor Lms MEDIUM 6.5
CVE-2024-3553

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil…

Fix: 2.7.0+
Fix from $1,600 2024-05-02
Tutor Lms MEDIUM 5.4
CVE-2024-3994

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tutor_instru…

Fix: 2.7.0+
Fix from $1,600 2024-04-25
Tutor Lms Elementor Addons MEDIUM 5.4
CVE-2024-29913

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS Elementor Addons allows Store…

Fix: 2.1.4+
Fix from $1,600 2024-03-27
Tutor Lms HIGH 8.8
CVE-2024-1751

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in …

Fix: 2.6.2+
Fix from $1,950 2024-03-13
Qubely MEDIUM 5.4
CVE-2023-0376

The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the …

Fix: 1.8.5+
Fix from $1,600 2024-01-16
Wp Crowdfunding MEDIUM 6.1
CVE-2023-6161

The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflec…

Fix: 2.1.9+
Fix from $1,600 2024-01-08
Wp Crowdfunding MEDIUM 5.4
CVE-2023-50859

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfunding allows Stored XSS.This …

Fix: after 2.1.6
Fix from $1,600 2023-12-28
Wp Crowdfunding MEDIUM 6.1
CVE-2023-47532

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themeum WP Crowdfunding plugin <= 2.1.6 versions.

Fix: after 2.1.6
Fix from $1,600 2023-11-14
Tutor Lms CRITICAL 9.8
CVE-2023-25700

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This iss…

Fix: after 2.1.10
Fix from $2,300 2023-11-03
Tutor Lms HIGH 8.8
CVE-2023-25800

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This iss…

Fix: after 2.2.0
Fix from $1,950 2023-11-03
Tutor Lms HIGH 8.8
CVE-2023-25990

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This iss…

Fix: after 2.1.10
Fix from $1,950 2023-11-03
Tutor Lms MEDIUM 5.4
CVE-2023-4805

The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform …

Fix: 2.3.0+
Fix from $1,600 2023-10-16
Qubely HIGH 7.5
CVE-2021-24916

The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data A…

Fix: 1.8.6+
Fix from $1,950 2023-08-07
Tutor Lms HIGH 7.5
CVE-2023-3133

The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers …

Fix: 2.2.1+
Fix from $1,950 2023-07-04
Tutor Lms MEDIUM 6.1
CVE-2023-0236

The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attribu…

Fix: 2.0.10+
Fix from $1,600 2023-02-06
Wp Page Builder MEDIUM 5.4
CVE-2022-40963

Multiple Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerabilities in WP Page Builder plugin <= 1.2.6 on WordPress.

Fix: 1.2.7+
Fix from $1,600 2022-11-18
Qubely MEDIUM 6.5
CVE-2021-25013

The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure…

Fix: 1.7.8+
Fix from $1,600 2022-01-24
Tutor Lms MEDIUM 6.1
CVE-2021-25017

The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading…

Fix: 1.9.12+
Fix from $1,600 2022-01-24
Tutor Lms MEDIUM 6.1
CVE-2021-24873

The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attributes in the Student Registration…

Fix: 1.9.11+
Fix from $1,600 2021-11-23
Tutor Lms MEDIUM 5.4
CVE-2021-24455

The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of Announcements (when outputting…

Fix: 1.9.2+
Fix from $1,600 2021-08-02
Wp Page Builder MEDIUM 5.4
CVE-2021-24208

The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML, including JavaScript, into p…

Fix: 1.2.4+
Fix from $1,600 2021-04-05
Tutor Lms HIGH 8.8
CVE-2021-24184

Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to m…

Fix: 1.7.7+
Fix from $1,950 2021-04-05
Tutor Lms MEDIUM 6.5
CVE-2021-24181

The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable t…

Fix: 1.7.7+
Fix from $1,600 2021-04-05
Tutor Lms MEDIUM 6.5
CVE-2021-24182

The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 wa…

Fix: 1.8.3+
Fix from $1,600 2021-04-05
Tutor Lms MEDIUM 6.5
CVE-2021-24183

The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vuln…

Fix: 1.8.3+
Fix from $1,600 2021-04-05
Tutor Lms MEDIUM 6.5
CVE-2021-24185

The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind an…

Fix: 1.7.7+
Fix from $1,600 2021-04-05
Tutor Lms MEDIUM 6.5
CVE-2021-24186

The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.…

Fix: 1.8.3+
Fix from $1,600 2021-04-05
Tutor Lms MEDIUM 6.5
CVE-2020-8615EPSS 9%

A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performin…

Fix: 1.5.3+
Fix from $1,600 2020-02-04