Vulnerabilidades en Themeum
126 resultadosAnálisis Vexday
Themeum apresenta 48 vulnerabilidades registradas, com 11 publicadas nos últimos 90 dias, indicando cadência moderada de descobertas. Nenhuma vulnerabilidade está sob ataque ativo no momento, embora 4 sejam críticas; a fraqueza predominante é injeção de conteúdo (CWE-79), típica de aplicações web. O risco atual é gerenciável, mas a presença de críticas e o padrão recente de descobertas justificam monitoramento contínuo.
CVE-2024-4222HIGHTutor LMS Pro <= 2.7.0 - Missing AuthorizationEPSS 0.3%CVE-2026-23799MEDIUMWordPress Tutor LMS plugin <= 3.9.5 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-9601MEDIUMQubely – Advanced Gutenberg Blocks <= 1.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' and 'UniqueID'EPSS 0.3%CVE-2024-1804MEDIUMTutor LMS – Migration Tool <= 2.2.0 - Missing Authorization in tutor_import_from_xmlEPSS 0.3%CVE-2024-11910MEDIUMWP Crowdfunding <= 2.1.15 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-10897MEDIUMTutor LMS Elementor Addons <= 2.1.5 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin InstallationEPSS 0.3%CVE-2026-1371MEDIUMTutor LMS <= 3.9.5 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX ActionEPSS 0.3%CVE-2024-43231MEDIUMWordPress Tutor LMS plugin <= 2.7.3 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-32223MEDIUMWordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2026-40740MEDIUMWordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-43954MEDIUMWordPress Droip plugin <= 1.1.1 - Subscriber+ Settings Change/Data Exposure VulnerabilityEPSS 0.3%CVE-2026-22332CRITICALWordPress Tutor LMS Pro plugin <= 3.9.6 - SQL Injection vulnerabilityEPSS 0.3%CVE-2026-0548MEDIUMTutor LMS – eLearning and online course solution <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment DeletionEPSS 0.3%CVE-2025-58993HIGHWordPress Tutor LMS Plugin <= 3.7.4 - SQL Injection VulnerabilityEPSS 0.3%CVE-2024-11911MEDIUMWP Crowdfunding <= 2.1.12 - Missing Authorization to Authenticated (Subscriber+) WooCommerce InstallationEPSS 0.3%CVE-2023-50859MEDIUMWordPress WP Crowdfunding Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)EPSS 0.3%CVE-2025-11564MEDIUMTutor LMS – eLearning and online course solution <= 3.8.3 - Missing Authorization to Unauthenticated Payment Status UpdateEPSS 0.3%CVE-2025-58249MEDIUMWordPress Qubely Plugin <= 1.8.14 - Sensitive Data Exposure VulnerabilityEPSS 0.3%CVE-2025-32230MEDIUMWordPress Tutor LMS plugin <= 3.4.0 - HTML Injection vulnerabilityEPSS 0.3%CVE-2026-40743MEDIUMWordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerabilityEPSS 0.3%