themeum records
80 published records for vendor themeum.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 30%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')26
- CWE-862 Missing Authorization21
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')15
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-284 Improper Access Control3
The weakness classes this vendor ships most often: where to look.
CWEAll records
80 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2024-10400Proof of concept | Tutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filterthemeum · tutor lms · CWE-89 | High7.5 | — | 83.1% | Nov 21, 2024 |
39Monitor | CVE-2023-25700No exploit | WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injectionthemeum · tutor lms · CWE-89 | Critical9.8 | — | 0.8% | Nov 3, 2023 |
39Monitor | CVE-2024-4223No exploit | Tutor LMS <= 2.7.0 - Missing Authorizationthemeum · tutor lms · CWE-862 | Critical9.8 | — | 0.5% | May 16, 2024 |
36Monitor | CVE-2024-1751Proof of concept | Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injectionthemeum · tutor lms · CWE-89 | High8.8 | — | 3.1% | Mar 13, 2024 |
35Monitor | CVE-2021-24184No exploit | Tutor LMS < 1.7.7 - Unprotected AJAX including Privilege Escalationthemeum · tutor lms · CWE-862 | High8.8 | — | 1.4% | Apr 5, 2021 |
35Monitor | CVE-2024-4352No exploit | Tutor LMS Pro <= 2.7.0 - Missing Authorization to SQL Injectionthemeum · tutor lms · CWE-862 | High8.8 | — | 1.2% | May 16, 2024 |
35Monitor | CVE-2024-4351Proof of concept | Tutor LMS Pro <= 2.7.0 - Missing Authorization to Privilege Escalationthemeum · tutor lms · CWE-89 | High8.8 | — | 1.0% | May 16, 2024 |
35Monitor | CVE-2023-41870No exploit | WordPress WP Crowdfunding plugin <= 2.1.5 - Broken Access Control vulnerabilitythemeum · wp crowdfunding · CWE-862 | High8.8 | — | 0.8% | Dec 13, 2024 |
35Monitor | CVE-2023-25800No exploit | WordPress Tutor LMS Plugin <= 2.2.0 is vulnerable to SQL Injectionthemeum · tutor lms · CWE-89 | High8.8 | — | 0.7% | Nov 3, 2023 |
35Monitor | CVE-2023-25990No exploit | WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injectionthemeum · tutor lms · CWE-89 | High8.8 | — | 0.7% | Nov 3, 2023 |
35Monitor | CVE-2025-5831No exploit | Droip < 2.5.2 - Authenticated (Subscriber+) Arbitrary File Uploadthemeum · droip · CWE-434 | High8.8 | — | 0.6% | Jul 25, 2025 |
35Monitor | CVE-2024-53816No exploit | WordPress Tutor LMS Elementor Addons plugin <= 2.1.5 - Broken Access Control vulnerabilitythemeum · tutor lms elementor addons · CWE-862 | High8.8 | — | 0.5% | Dec 9, 2024 |
35Monitor | CVE-2023-25799No exploit | WordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilitiesthemeum · tutor lms · CWE-862 | High8.8 | — | 0.5% | Jun 11, 2024 |
35Monitor | CVE-2024-43142No exploit | WordPress Tutor LMS plugin <= 2.7.3 - Broken Access Control vulnerabilitythemeum · tutor lms · CWE-862 | High8.8 | — | 0.4% | Nov 1, 2024 |
35Monitor | CVE-2025-5835No exploit | Droip <= 2.2.6 - Missing Authorization to Authenticated (Subscriber+) Many Actionsthemeum · droip · CWE-862 | High8.8 | — | 0.4% | Jul 25, 2025 |
35Monitor | CVE-2024-39645No exploit | WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Request Forgery (CSRF) vulnerabilitythemeum · tutor lms · CWE-352 | High8.8 | — | 0.2% | Aug 26, 2024 |
32Monitor | CVE-2024-4222No exploit | Tutor LMS Pro <= 2.7.0 - Missing Authorizationthemeum · tutor lms · CWE-862 | High8.2 | — | 0.3% | May 16, 2024 |
31Monitor | CVE-2021-24916Proof of concept | Qubely < 1.8.6 - Unauthenticated Arbitrary E-mail Sendingthemeum · qubely · CWE-284 | High7.5 | — | 1.7% | Aug 7, 2023 |
30Monitor | CVE-2023-3133No exploit | Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST APIthemeum · tutor lms · CWE-639 | High7.5 | — | 1.0% | Jul 4, 2023 |
30Monitor | CVE-2024-43955No exploit | WordPress Droip plugin <= 1.1.1 - Unauthenticated Arbitrary File Download/Deletion vulnerabilitythemeum · droip · CWE-22 | High7.5 | — | 0.6% | Aug 29, 2024 |
29Monitor | CVE-2020-8615Proof of concept | A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and themeum · tutor lms · CWE-352 | Medium6.5 | — | 8.8% | Feb 4, 2020 |
28Monitor | CVE-2024-37266No exploit | WordPress Tutor LMS plugin <= 2.7.1 - Path Traversal vulnerabilitythemeum · tutor lms · CWE-22 | High7.2 | — | 0.6% | Jul 9, 2024 |
28Monitor | CVE-2024-37256No exploit | WordPress Tutor LMS plugin <= 2.7.1 - SQL Injection vulnerabilitythemeum · tutor lms · CWE-89 | High7.2 | — | 0.6% | Jul 9, 2024 |
28Monitor | CVE-2024-4902No exploit | Tutor LMS – eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL Injectionthemeum · tutor lms · CWE-89 | High7.2 | — | 0.5% | Jun 7, 2024 |
28Monitor | CVE-2024-43282No exploit | WordPress Tutor LMS plugin <= 2.7.2 - SQL Injection vulnerabilitythemeum · tutor lms · CWE-89 | High7.2 | — | 0.4% | Aug 18, 2024 |
- CVE-2024-1040055Plan
Tutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filter
HighCVSS 7.5Proof of conceptEPSS 83%themeum · tutor lmsNov 21, 2024
- CVE-2023-2570039Monitor
WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%themeum · tutor lmsNov 3, 2023
- CVE-2024-422339Monitor
Tutor LMS <= 2.7.0 - Missing Authorization
CriticalCVSS 9.8No exploitEPSS 1%themeum · tutor lmsMay 16, 2024
- CVE-2024-175136Monitor
Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injection
HighCVSS 8.8Proof of conceptEPSS 3%themeum · tutor lmsMar 13, 2024
- CVE-2021-2418435Monitor
Tutor LMS < 1.7.7 - Unprotected AJAX including Privilege Escalation
HighCVSS 8.8No exploitEPSS 1%themeum · tutor lmsApr 5, 2021
- CVE-2024-435235Monitor
Tutor LMS Pro <= 2.7.0 - Missing Authorization to SQL Injection
HighCVSS 8.8No exploitEPSS 1%themeum · tutor lmsMay 16, 2024
- CVE-2024-435135Monitor
Tutor LMS Pro <= 2.7.0 - Missing Authorization to Privilege Escalation
HighCVSS 8.8Proof of conceptEPSS 1%themeum · tutor lmsMay 16, 2024
- CVE-2023-4187035Monitor
WordPress WP Crowdfunding plugin <= 2.1.5 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 1%themeum · wp crowdfundingDec 13, 2024
- CVE-2023-2580035Monitor
WordPress Tutor LMS Plugin <= 2.2.0 is vulnerable to SQL Injection
HighCVSS 8.8No exploitEPSS 1%themeum · tutor lmsNov 3, 2023
- CVE-2023-2599035Monitor
WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injection
HighCVSS 8.8No exploitEPSS 1%themeum · tutor lmsNov 3, 2023
- CVE-2025-583135Monitor
Droip < 2.5.2 - Authenticated (Subscriber+) Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%themeum · droipJul 25, 2025
- CVE-2024-5381635Monitor
WordPress Tutor LMS Elementor Addons plugin <= 2.1.5 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%themeum · tutor lms elementor addonsDec 9, 2024
- CVE-2023-2579935Monitor
WordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilities
HighCVSS 8.8No exploitEPSS 0%themeum · tutor lmsJun 11, 2024
- CVE-2024-4314235Monitor
WordPress Tutor LMS plugin <= 2.7.3 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%themeum · tutor lmsNov 1, 2024
- CVE-2025-583535Monitor
Droip <= 2.2.6 - Missing Authorization to Authenticated (Subscriber+) Many Actions
HighCVSS 8.8No exploitEPSS 0%themeum · droipJul 25, 2025
- CVE-2024-3964535Monitor
WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%themeum · tutor lmsAug 26, 2024
- CVE-2024-422232Monitor
Tutor LMS Pro <= 2.7.0 - Missing Authorization
HighCVSS 8.2No exploitEPSS 0%themeum · tutor lmsMay 16, 2024
- CVE-2021-2491631Monitor
Qubely < 1.8.6 - Unauthenticated Arbitrary E-mail Sending
HighCVSS 7.5Proof of conceptEPSS 2%themeum · qubelyAug 7, 2023
- CVE-2023-313330Monitor
Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST API
HighCVSS 7.5No exploitEPSS 1%themeum · tutor lmsJul 4, 2023
- CVE-2024-4395530Monitor
WordPress Droip plugin <= 1.1.1 - Unauthenticated Arbitrary File Download/Deletion vulnerability
HighCVSS 7.5No exploitEPSS 1%themeum · droipAug 29, 2024
- CVE-2020-861529Monitor
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and
MediumCVSS 6.5Proof of conceptEPSS 9%themeum · tutor lmsFeb 4, 2020
- CVE-2024-3726628Monitor
WordPress Tutor LMS plugin <= 2.7.1 - Path Traversal vulnerability
HighCVSS 7.2No exploitEPSS 1%themeum · tutor lmsJul 9, 2024
- CVE-2024-3725628Monitor
WordPress Tutor LMS plugin <= 2.7.1 - SQL Injection vulnerability
HighCVSS 7.2No exploitEPSS 1%themeum · tutor lmsJul 9, 2024
- CVE-2024-490228Monitor
Tutor LMS – eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL Injection
HighCVSS 7.2No exploitEPSS 0%themeum · tutor lmsJun 7, 2024
- CVE-2024-4328228Monitor
WordPress Tutor LMS plugin <= 2.7.2 - SQL Injection vulnerability
HighCVSS 7.2No exploitEPSS 0%themeum · tutor lmsAug 18, 2024