Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Themeum — Vulnerabilities & Security Advisories 126

Browse all 126 CVE security advisories affecting Themeum. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Themeum operates as a cloud-based platform facilitating the creation and deployment of virtual machines, primarily targeting developers and enterprises seeking streamlined infrastructure management. Security audits have identified eighty-four Common Vulnerabilities and Exposures (CVEs) associated with the platform, indicating a significant historical attack surface. The most prevalent vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from inadequate input validation and improper access controls within its web interface and API endpoints. These defects have occasionally allowed unauthorized users to execute arbitrary commands or escalate their permissions to administrative levels, potentially compromising underlying virtual machine instances. While specific major public breaches remain limited in detailed public reporting, the high volume of disclosed CVEs suggests persistent challenges in securing the application layer. Continuous patching and rigorous code review processes are essential to mitigate these recurring risks and ensure the integrity of hosted environments.

Found 43 results / 126 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-18439 Tutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' Parameter — Tutor LMS – eLearning and online course solution CWE-639 4.3 Medium 2026-09-22
CVE-2026-89081 Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters — Tutor LMS – eLearning and online course solution CWE-79 6.1 Medium 2026-09-19
CVE-2026-88944 Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter — Tutor LMS – eLearning and online course solution CWE-862 4.3 Medium 2026-09-19
CVE-2026-89333 Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter — Tutor LMS – eLearning and online course solution CWE-639 6.5 Medium 2026-09-19
CVE-2026-78175 Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution — Tutor LMS – eLearning and online course solution CWE-502 8.8 High 2026-09-12
CVE-2026-16759 Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters — Tutor LMS – eLearning and online course solution CWE-74 6.5 Medium 2026-08-28
CVE-2026-15444 Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter — Tutor LMS – eLearning and online course solution CWE-89 4.9 Medium 2026-07-28
CVE-2026-15022 Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array — Tutor LMS – eLearning and online course solution CWE-89 6.5 Medium 2026-07-16
CVE-2026-13443 Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title — Tutor LMS – eLearning and online course solution CWE-79 6.4 Medium 2026-07-01
CVE-2026-10736 Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' Parameter — Tutor LMS – eLearning and online course solution CWE-89 4.9 Medium 2026-06-18
CVE-2026-6965 Tutor LMS <= 3.9.9 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter — Tutor LMS – eLearning and online course solution CWE-639 5.3 Medium 2026-05-13
CVE-2026-5502 Tutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_order — Tutor LMS – eLearning and online course solution CWE-862 5.3 Medium 2026-04-17
CVE-2026-6080 Tutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' Parameter — Tutor LMS – eLearning and online course solution CWE-89 6.5 Medium 2026-04-17
CVE-2026-3371 Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification — Tutor LMS – eLearning and online course solution CWE-639 4.3 Medium 2026-04-11
CVE-2026-3358 Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment — Tutor LMS – eLearning and online course solution CWE-862 5.4 Medium 2026-04-11
CVE-2026-3360 Tutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter — Tutor LMS – eLearning and online course solution CWE-862 7.5 High 2026-04-10
CVE-2025-13673 Tutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_code — Tutor LMS – eLearning and online course solution CWE-89 7.5 High 2026-02-28
CVE-2026-1371 Tutor LMS <= 3.9.5 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action — Tutor LMS – eLearning and online course solution CWE-200 5.3 Medium 2026-02-03
CVE-2026-1375 Tutor LMS <= 3.9.5 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion — Tutor LMS – eLearning and online course solution CWE-639 8.1 High 2026-02-03
CVE-2026-0548 Tutor LMS – eLearning and online course solution <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion — Tutor LMS – eLearning and online course solution CWE-862 5.4 Medium 2026-01-20
CVE-2025-13935 Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Course Completion — Tutor LMS – eLearning and online course solution CWE-862 4.3 Medium 2026-01-09
CVE-2025-13934 Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass — Tutor LMS – eLearning and online course solution CWE-862 4.3 Medium 2026-01-09
CVE-2025-13628 Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification — Tutor LMS – eLearning and online course solution CWE-862 4.3 Medium 2026-01-09
CVE-2025-13679 Tutor LMS <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_details — Tutor LMS – eLearning and online course solution CWE-862 6.5 Medium 2026-01-08
CVE-2025-11564 Tutor LMS – eLearning and online course solution <= 3.8.3 - Missing Authorization to Unauthenticated Payment Status Update — Tutor LMS – eLearning and online course solution CWE-862 5.3 Medium 2025-10-25
CVE-2025-6680 Tutor LMS <= 3.8.3 - Missing Authorization to Sensitive Information Exposure — Tutor LMS – eLearning and online course solution CWE-284 4.3 Medium 2025-10-25
CVE-2024-10400 Tutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filter — Tutor LMS – eLearning and online course solution CWE-89 7.5 High 2024-11-21
CVE-2024-10393 Tutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User Registration — Tutor LMS – eLearning and online course solution CWE-284 5.3 Medium 2024-11-21
CVE-2023-2919 Tutor LMS <= 2.7.4 - Cross-Site Request Forgery via 'addon_enable_disable' — Tutor LMS – eLearning and online course solution CWE-352 4.3 Medium 2024-09-10
CVE-2024-5438 Tutor LMS – eLearning and online course solution <= 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt Deletion — Tutor LMS – eLearning and online course solution CWE-639 4.3 Medium 2024-06-07

This page lists every published CVE security advisory associated with Themeum. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.