Tutor lms – elearning and online course solution
This hub aggregates every CVE we track for Tutor lms – elearning and online course solution, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
34
CVEs tracked
1
Critical
7
High
0
In CISA KEV
Severity distribution
MEDIUM25HIGH7LOW1CRITICAL1
Monthly trend
0
0
1
0
2
0
0
0
0
0
0
0
0
0
0
2
0
0
5
3
0
5
1
1
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Tutor lms – elearning and online course solution.
- CVE-2026-10736Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' Parameter4.9
- CVE-2026-6965Tutor LMS <= 3.9.9 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter5.3
- CVE-2026-5502Tutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_order5.3
- CVE-2026-6080Tutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' Parameter6.5
- CVE-2026-3371Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification4.3
- CVE-2026-3358Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment5.4
- CVE-2026-3360Tutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter7.5
- CVE-2025-13673Tutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_code7.5
- CVE-2026-1371Tutor LMS <= 3.9.5 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action5.3
- CVE-2026-1375Tutor LMS <= 3.9.5 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion8.1
- CVE-2026-0548Tutor LMS – eLearning and online course solution <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion5.4
- CVE-2025-13934Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass4.3
- CVE-2025-13935Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Course Completion4.3
- CVE-2025-13628Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification4.3
- CVE-2025-13679Tutor LMS <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_details6.5
Product normalization is registry-driven with AI assist and human review. How it works