CVE Tools

Tutor Lms – Elearning and Online Course Solution

43 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Tutor Lms – Elearning and Online Course Solution, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Tutor Lms – Elearning and Online Course Solution CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Tutor Lms – Elearning and Online Course Solution CVEs per month
MonthCVEs
2024-100
2024-112
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-102
2025-110
2025-120
2026-015
2026-023
2026-030
2026-045
2026-051
2026-061
2026-073
2026-081
2026-095

Severity

How the 43 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical12%
  • High819%
  • Medium3377%
  • Low12%

Latest CVEs

The 15 most recently published vulnerabilities affecting Tutor Lms – Elearning and Online Course Solution.

  1. CVE-2026-18439Tutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' Parameter4.3
  2. CVE-2026-89081Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters6.1
  3. CVE-2026-88944Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter4.3
  4. CVE-2026-89333Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter6.5
  5. CVE-2026-78175Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution8.8
  6. CVE-2026-16759Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters6.5
  7. CVE-2026-15444Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter4.9
  8. CVE-2026-15022Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array6.5
  9. CVE-2026-13443Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title6.4
  10. CVE-2026-10736Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' Parameter4.9
  11. CVE-2026-6965Tutor LMS <= 3.9.9 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter5.3
  12. CVE-2026-5502Tutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_order5.3
  13. CVE-2026-6080Tutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' Parameter6.5
  14. CVE-2026-3371Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification4.3
  15. CVE-2026-3358Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store