SecAlerts
Tutor LMS logo

Tutor LMS

Security Risk Profile

36
/100
low

Security Risk Score

Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 16, 2024 to present

19
Total CVEs
8
Critical+High
0
Exploited
7
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
7
Critical/High
Risk Level
36/100
low
🆕 1Fresh (<7d)📈 5 in Last 30 Days

Severity Distribution

Critical
1
High
7
Medium
11
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
SQL Injection
6
2
XSS
2

Most Affected Products

1. Themeum Tutor Lms Wordpress10
2. Tutor LMS Tutor LMS6
3. Tutor LMS Tutor LMS Pro5
4. Tutor LMS WordPress plugin4
5. Tutor LMS Tutor LMS (WordPress plugin)1

Recent Vulnerabilities

See more →
CVE-2026-14306
CVSS 4.3medium

Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass

8/6/2026🔧 No Patch
CVE-2026-15022
CVSS 6.5medium

Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array

7/16/2026🔧 No Patch
CVE-2026-12275
CVSS 7.1high

Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration

7/13/2026🔧 No Patch
CVE-2026-12274
CVSS 6.5medium

Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR

7/13/2026🔧 No Patch
CVE-2026-12271
CVSS 5.4medium

Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR

7/13/2026🔧 No Patch
CVE-2026-13443
CVSS 6.4medium

Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title

7/1/2026🔧 No Patch
CVE-2025-6639
CVSS 5.4medium

Tutor LMS Pro – eLearning and online course solution <= 3.8.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to View/Edit Other Assignments

10/25/2025🔧 No Patch
CVE-2025-11564
CVSS 5.3medium

Tutor LMS – eLearning and online course solution <= 3.8.3 - Missing Authorization to Unauthenticated Payment Status Update

10/25/2025🔧 No Patch
CVE-2025-6680
CVSS 4.3medium

Tutor LMS <= 3.8.3 - Missing Authorization to Sensitive Information Exposure

10/25/2025
CVE-2025-6184
CVSS 8.8high

Tutor LMS Pro – eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL Injection

8/13/2025🔧 No Patch

Monitor Tutor LMS in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Tutor LMS Security Vulnerabilities & Risk Score | 19 CVEs | SecAlerts - SecAlerts