Vulnerabilidades en Themeum

126 resultados
Análisis Vexday

Themeum apresenta 48 vulnerabilidades registradas, com 11 publicadas nos últimos 90 dias, indicando cadência moderada de descobertas. Nenhuma vulnerabilidade está sob ataque ativo no momento, embora 4 sejam críticas; a fraqueza predominante é injeção de conteúdo (CWE-79), típica de aplicações web. O risco atual é gerenciável, mas a presença de críticas e o padrão recente de descobertas justificam monitoramento contínuo.

CVE-2026-12472MEDIUMKirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' ParametersEPSS 0.6%CVE-2024-10393MEDIUMTutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User RegistrationEPSS 0.6%CVE-2024-37256HIGHWordPress Tutor LMS plugin <= 2.7.1 - SQL Injection vulnerabilityEPSS 0.6%CVE-2026-15022MEDIUMTutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer ArrayEPSS 0.6%CVE-2026-57724CRITICALWordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-8073HIGHKirki <= 6.0.6 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIPEPSS 0.5%CVE-2026-18347MEDIUMKirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'context' ParameterEPSS 0.5%CVE-2026-6965MEDIUMTutor LMS <= 3.9.9 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET ParameterEPSS 0.5%CVE-2024-4223CRITICALTutor LMS <= 2.7.0 - Missing AuthorizationEPSS 0.5%CVE-2024-4318HIGHTutor LMS <= 2.7.0 - Authenticated (Instructor+) SQL InjectionEPSS 0.5%CVE-2026-65436MEDIUMWordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2024-1128MEDIUMTutor LMS <= 2.6.0 - Authenticated(Student+) HTML Injection via Q&AEPSS 0.5%CVE-2026-12122MEDIUMKirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX ActionEPSS 0.5%CVE-2024-4902HIGHTutor LMS – eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL InjectionEPSS 0.5%CVE-2024-53816MEDIUMWordPress Tutor LMS Elementor Addons plugin <= 2.1.5 - Broken Access Control vulnerabilityEPSS 0.5%CVE-2026-10736MEDIUMTutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' ParameterEPSS 0.5%CVE-2026-15444MEDIUMTutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' ParameterEPSS 0.5%CVE-2026-13464MEDIUMKirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' ParameterEPSS 0.5%CVE-2025-13673HIGHTutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_codeEPSS 0.5%CVE-2026-6080MEDIUMTutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' ParameterEPSS 0.5%