themeum kayıtları
themeum üreticisine ait 80 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %30
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')26
- CWE-862 Missing Authorization21
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')15
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-284 Improper Access Control3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
80 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2024-10400Kavram kanıtı | Tutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filterthemeum · tutor lms · CWE-89 | Yüksek7,5 | — | %83,1 | 21 Kas 2024 |
39İzleyin | CVE-2023-25700İstismar yok | WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injectionthemeum · tutor lms · CWE-89 | Kritik9,8 | — | %0,8 | 3 Kas 2023 |
39İzleyin | CVE-2024-4223İstismar yok | Tutor LMS <= 2.7.0 - Missing Authorizationthemeum · tutor lms · CWE-862 | Kritik9,8 | — | %0,5 | 16 May 2024 |
36İzleyin | CVE-2024-1751Kavram kanıtı | Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injectionthemeum · tutor lms · CWE-89 | Yüksek8,8 | — | %3,1 | 13 Mar 2024 |
35İzleyin | CVE-2021-24184İstismar yok | Tutor LMS < 1.7.7 - Unprotected AJAX including Privilege Escalationthemeum · tutor lms · CWE-862 | Yüksek8,8 | — | %1,4 | 5 Nis 2021 |
35İzleyin | CVE-2024-4352İstismar yok | Tutor LMS Pro <= 2.7.0 - Missing Authorization to SQL Injectionthemeum · tutor lms · CWE-862 | Yüksek8,8 | — | %1,2 | 16 May 2024 |
35İzleyin | CVE-2024-4351Kavram kanıtı | Tutor LMS Pro <= 2.7.0 - Missing Authorization to Privilege Escalationthemeum · tutor lms · CWE-89 | Yüksek8,8 | — | %1,0 | 16 May 2024 |
35İzleyin | CVE-2023-41870İstismar yok | WordPress WP Crowdfunding plugin <= 2.1.5 - Broken Access Control vulnerabilitythemeum · wp crowdfunding · CWE-862 | Yüksek8,8 | — | %0,8 | 13 Ara 2024 |
35İzleyin | CVE-2023-25800İstismar yok | WordPress Tutor LMS Plugin <= 2.2.0 is vulnerable to SQL Injectionthemeum · tutor lms · CWE-89 | Yüksek8,8 | — | %0,7 | 3 Kas 2023 |
35İzleyin | CVE-2023-25990İstismar yok | WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injectionthemeum · tutor lms · CWE-89 | Yüksek8,8 | — | %0,7 | 3 Kas 2023 |
35İzleyin | CVE-2025-5831İstismar yok | Droip < 2.5.2 - Authenticated (Subscriber+) Arbitrary File Uploadthemeum · droip · CWE-434 | Yüksek8,8 | — | %0,6 | 25 Tem 2025 |
35İzleyin | CVE-2024-53816İstismar yok | WordPress Tutor LMS Elementor Addons plugin <= 2.1.5 - Broken Access Control vulnerabilitythemeum · tutor lms elementor addons · CWE-862 | Yüksek8,8 | — | %0,5 | 9 Ara 2024 |
35İzleyin | CVE-2023-25799İstismar yok | WordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilitiesthemeum · tutor lms · CWE-862 | Yüksek8,8 | — | %0,5 | 11 Haz 2024 |
35İzleyin | CVE-2024-43142İstismar yok | WordPress Tutor LMS plugin <= 2.7.3 - Broken Access Control vulnerabilitythemeum · tutor lms · CWE-862 | Yüksek8,8 | — | %0,4 | 1 Kas 2024 |
35İzleyin | CVE-2025-5835İstismar yok | Droip <= 2.2.6 - Missing Authorization to Authenticated (Subscriber+) Many Actionsthemeum · droip · CWE-862 | Yüksek8,8 | — | %0,4 | 25 Tem 2025 |
35İzleyin | CVE-2024-39645İstismar yok | WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Request Forgery (CSRF) vulnerabilitythemeum · tutor lms · CWE-352 | Yüksek8,8 | — | %0,2 | 26 Ağu 2024 |
32İzleyin | CVE-2024-4222İstismar yok | Tutor LMS Pro <= 2.7.0 - Missing Authorizationthemeum · tutor lms · CWE-862 | Yüksek8,2 | — | %0,3 | 16 May 2024 |
31İzleyin | CVE-2021-24916Kavram kanıtı | Qubely < 1.8.6 - Unauthenticated Arbitrary E-mail Sendingthemeum · qubely · CWE-284 | Yüksek7,5 | — | %1,7 | 7 Ağu 2023 |
30İzleyin | CVE-2023-3133İstismar yok | Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST APIthemeum · tutor lms · CWE-639 | Yüksek7,5 | — | %1,0 | 4 Tem 2023 |
30İzleyin | CVE-2024-43955İstismar yok | WordPress Droip plugin <= 1.1.1 - Unauthenticated Arbitrary File Download/Deletion vulnerabilitythemeum · droip · CWE-22 | Yüksek7,5 | — | %0,6 | 29 Ağu 2024 |
29İzleyin | CVE-2020-8615Kavram kanıtı | A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and themeum · tutor lms · CWE-352 | Orta6,5 | — | %8,8 | 4 Şub 2020 |
28İzleyin | CVE-2024-37266İstismar yok | WordPress Tutor LMS plugin <= 2.7.1 - Path Traversal vulnerabilitythemeum · tutor lms · CWE-22 | Yüksek7,2 | — | %0,6 | 9 Tem 2024 |
28İzleyin | CVE-2024-37256İstismar yok | WordPress Tutor LMS plugin <= 2.7.1 - SQL Injection vulnerabilitythemeum · tutor lms · CWE-89 | Yüksek7,2 | — | %0,6 | 9 Tem 2024 |
28İzleyin | CVE-2024-4902İstismar yok | Tutor LMS – eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL Injectionthemeum · tutor lms · CWE-89 | Yüksek7,2 | — | %0,5 | 7 Haz 2024 |
28İzleyin | CVE-2024-43282İstismar yok | WordPress Tutor LMS plugin <= 2.7.2 - SQL Injection vulnerabilitythemeum · tutor lms · CWE-89 | Yüksek7,2 | — | %0,4 | 18 Ağu 2024 |
- CVE-2024-1040055Planlayın
Tutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filter
YüksekCVSS 7,5Kavram kanıtıEPSS %83themeum · tutor lms21 Kas 2024
- CVE-2023-2570039İzleyin
WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injection
KritikCVSS 9,8İstismar yokEPSS %1themeum · tutor lms3 Kas 2023
- CVE-2024-422339İzleyin
Tutor LMS <= 2.7.0 - Missing Authorization
KritikCVSS 9,8İstismar yokEPSS %1themeum · tutor lms16 May 2024
- CVE-2024-175136İzleyin
Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injection
YüksekCVSS 8,8Kavram kanıtıEPSS %3themeum · tutor lms13 Mar 2024
- CVE-2021-2418435İzleyin
Tutor LMS < 1.7.7 - Unprotected AJAX including Privilege Escalation
YüksekCVSS 8,8İstismar yokEPSS %1themeum · tutor lms5 Nis 2021
- CVE-2024-435235İzleyin
Tutor LMS Pro <= 2.7.0 - Missing Authorization to SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %1themeum · tutor lms16 May 2024
- CVE-2024-435135İzleyin
Tutor LMS Pro <= 2.7.0 - Missing Authorization to Privilege Escalation
YüksekCVSS 8,8Kavram kanıtıEPSS %1themeum · tutor lms16 May 2024
- CVE-2023-4187035İzleyin
WordPress WP Crowdfunding plugin <= 2.1.5 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1themeum · wp crowdfunding13 Ara 2024
- CVE-2023-2580035İzleyin
WordPress Tutor LMS Plugin <= 2.2.0 is vulnerable to SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %1themeum · tutor lms3 Kas 2023
- CVE-2023-2599035İzleyin
WordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %1themeum · tutor lms3 Kas 2023
- CVE-2025-583135İzleyin
Droip < 2.5.2 - Authenticated (Subscriber+) Arbitrary File Upload
YüksekCVSS 8,8İstismar yokEPSS %1themeum · droip25 Tem 2025
- CVE-2024-5381635İzleyin
WordPress Tutor LMS Elementor Addons plugin <= 2.1.5 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0themeum · tutor lms elementor addons9 Ara 2024
- CVE-2023-2579935İzleyin
WordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilities
YüksekCVSS 8,8İstismar yokEPSS %0themeum · tutor lms11 Haz 2024
- CVE-2024-4314235İzleyin
WordPress Tutor LMS plugin <= 2.7.3 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0themeum · tutor lms1 Kas 2024
- CVE-2025-583535İzleyin
Droip <= 2.2.6 - Missing Authorization to Authenticated (Subscriber+) Many Actions
YüksekCVSS 8,8İstismar yokEPSS %0themeum · droip25 Tem 2025
- CVE-2024-3964535İzleyin
WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Request Forgery (CSRF) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0themeum · tutor lms26 Ağu 2024
- CVE-2024-422232İzleyin
Tutor LMS Pro <= 2.7.0 - Missing Authorization
YüksekCVSS 8,2İstismar yokEPSS %0themeum · tutor lms16 May 2024
- CVE-2021-2491631İzleyin
Qubely < 1.8.6 - Unauthenticated Arbitrary E-mail Sending
YüksekCVSS 7,5Kavram kanıtıEPSS %2themeum · qubely7 Ağu 2023
- CVE-2023-313330İzleyin
Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST API
YüksekCVSS 7,5İstismar yokEPSS %1themeum · tutor lms4 Tem 2023
- CVE-2024-4395530İzleyin
WordPress Droip plugin <= 1.1.1 - Unauthenticated Arbitrary File Download/Deletion vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1themeum · droip29 Ağu 2024
- CVE-2020-861529İzleyin
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and
OrtaCVSS 6,5Kavram kanıtıEPSS %9themeum · tutor lms4 Şub 2020
- CVE-2024-3726628İzleyin
WordPress Tutor LMS plugin <= 2.7.1 - Path Traversal vulnerability
YüksekCVSS 7,2İstismar yokEPSS %1themeum · tutor lms9 Tem 2024
- CVE-2024-3725628İzleyin
WordPress Tutor LMS plugin <= 2.7.1 - SQL Injection vulnerability
YüksekCVSS 7,2İstismar yokEPSS %1themeum · tutor lms9 Tem 2024
- CVE-2024-490228İzleyin
Tutor LMS – eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL Injection
YüksekCVSS 7,2İstismar yokEPSS %0themeum · tutor lms7 Haz 2024
- CVE-2024-4328228İzleyin
WordPress Tutor LMS plugin <= 2.7.2 - SQL Injection vulnerability
YüksekCVSS 7,2İstismar yokEPSS %0themeum · tutor lms18 Ağu 2024