CVEs we hold for Tutor
Records whose assigning authority named Tutor as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-85572Tutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment DisclosureUnknown Tutor LMS
CVE-2026-85569Tutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request MisclassificationUnknown Tutor LMS
CVE-2026-19094Tutor LMS < 4.0.6 - Unauthenticated SQLi via 'offset' and 'item_per_page' ParametersUnknown Tutor LMS
CVE-2026-19092Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable ShadowingUnknown Tutor LMS
CVE-2026-14310Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply InjectionUnknown Tutor LMS
CVE-2026-14306Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check BypassUnknown Tutor LMS
CVE-2026-14187Tutor LMS < 4.0.6 - Instructor+ Cross-Instructor Private Course Disclosure via IDORUnknown Tutor LMS
CVE-2026-12275Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki…Unknown Tutor LMS
CVE-2026-12273Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment CreationUnknown Tutor LMS
CVE-2026-12271Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDORUnknown Tutor LMS
CVE-2025-3537Tutorials-Website Employee Management System update-user.php improper authorizationTutorials-Website Employee Management System
CVE-2025-3536Tutorials-Website Employee Management System delete-user.php improper authorizationTutorials-Website Employee Management System
CVE-2025-11030Tutorials-Website Employee Management System HTTP Request all-applied-leave.php improper authorizationTutorials-Website Employee Management System
CVE-2023-3133Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST APIUnknown Tutor LMS
CVE-2022-2563Tutor LMS < 2.0.10 - Admin+ Stored Cross-Site ScriptingUnknown Tutor LMS – eLearning and online course solution
CVE-2021-25017Tutor LMS < 1.9.12 - Reflected Cross-Site ScriptingUnknown Tutor LMS – eLearning and online course solution
CVE-2021-24873Tutor LMS < 1.9.11 - Reflected Cross-Site ScriptingUnknown Tutor LMS – eLearning and online course solution
CVE-2021-24740Tutor LMS < 1.9.9 - Multiple Admin+ Stored Cross-Site ScriptingUnknown Tutor LMS – eLearning and online course solution
CVE-2021-24455Tutor LMS < 1.9.2 - Authenticated Stored Cross-Site Scripting (XSS)Unknown Tutor LMS – eLearning and online course solution
CVE-2021-24186Tutor LMS < 1.8.3 - SQL Injection via tutor_answering_quiz_question/get_answer_by_idUnknown Tutor LMS – eLearning and online course solution
CVE-2021-24185Tutor LMS < 1.7.7 - SQL Injection via tutor_place_ratingUnknown Tutor LMS – eLearning and online course solution
CVE-2021-24184Tutor LMS < 1.7.7 - Unprotected AJAX including Privilege EscalationUnknown Tutor LMS – eLearning and online course solution
CVE-2021-24183Tutor LMS < 1.8.3 - SQL Injection via tutor_quiz_builder_get_question_formUnknown Tutor LMS – eLearning and online course solution
CVE-2021-24182Tutor LMS < 1.8.3 - SQL Injection via tutor_quiz_builder_get_answers_by_questionUnknown Tutor LMS – eLearning and online course solution
CVE-2021-24181Tutor LMS < 1.7.7 - SQL Injection via tutor_mark_answer_as_correctUnknown Tutor LMS – eLearning and online course solution
29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.