Tutor lms – elearning and online course solution
This hub aggregates every CVE we track for Tutor lms – elearning and online course solution, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
38
CVEs tracked
1
Critical
7
High
0
In CISA KEV
Severity distribution
MEDIUM29HIGH7LOW1CRITICAL1
Monthly trend
0
2
0
0
0
0
0
0
0
0
0
0
2
0
0
5
3
0
5
1
1
3
1
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Tutor lms – elearning and online course solution.
- CVE-2026-16759Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters6.5
- CVE-2026-15444Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter4.9
- CVE-2026-15022Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array6.5
- CVE-2026-13443Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title6.4
- CVE-2026-10736Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' Parameter4.9
- CVE-2026-6965Tutor LMS <= 3.9.9 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter5.3
- CVE-2026-5502Tutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_order5.3
- CVE-2026-6080Tutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' Parameter6.5
- CVE-2026-3371Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification4.3
- CVE-2026-3358Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment5.4
- CVE-2026-3360Tutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter7.5
- CVE-2025-13673Tutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_code7.5
- CVE-2026-1375Tutor LMS <= 3.9.5 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion8.1
- CVE-2026-1371Tutor LMS <= 3.9.5 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action5.3
- CVE-2026-0548Tutor LMS – eLearning and online course solution <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion5.4
Product normalization is registry-driven with AI assist and human review. How it works