Vulnerabilities (CVE)

Filtered by vendor Themeum Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-25800 1 Themeum 1 Tutor Lms 2023-11-14 N/A 8.8 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.2.0.
CVE-2023-25990 1 Themeum 1 Tutor Lms 2023-11-13 N/A 8.8 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10.
CVE-2021-24916 1 Themeum 1 Qubely 2023-08-09 N/A 7.5 HIGH
The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.
CVE-2021-24184 1 Themeum 1 Tutor Lms 2022-05-03 6.5 MEDIUM 8.8 HIGH
Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.