Atutor / ATutor
28 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-64972 | Reflected XSS in ATutor | MEDIUM | 4.8 | Aug 20, 2026 |
| CVE-2026-64971 | Reflected XSS in ATutor | MEDIUM | 4.8 | Aug 20, 2026 |
| CVE-2026-64970 | Stored XSS in ATutor | MEDIUM | 5.1 | Aug 20, 2026 |
| CVE-2026-64969 | Insecure Direct Object Reference in ATutor | MEDIUM | 5.3 | Aug 20, 2026 |
| CVE-2026-64968 | Server-Side Request Forgery in ATutor | MEDIUM | 5.1 | Aug 20, 2026 |
| CVE-2026-64967 | Path Traversal in ATutor | MEDIUM | 6.9 | Aug 20, 2026 |
| CVE-2026-64966 | Path Traversal leading to Remote Code Execution in ATutor | HIGH | 8.7 | Aug 20, 2026 |
| CVE-2026-64965 | Missing Authorization Check in ATutor | MEDIUM | 5.3 | Aug 20, 2026 |
| CVE-2026-64964 | Generation of Predictable Email Confirmation Token in ATutor | MEDIUM | 6.3 | Aug 20, 2026 |
| CVE-2026-64963 | Path Traversal in ATutor | LOW | 2.3 | Aug 20, 2026 |
| CVE-2026-64962 | Cross-Site Request Forgery (CSRF) in ATutor | MEDIUM | 5.1 | Aug 20, 2026 |
| CVE-2026-64961 | Authentication Bypass in ATutor | MEDIUM | 6.3 | Aug 20, 2026 |
| CVE-2026-64960 | Remote Code Execution via Unrestricted File Upload in ATutor | HIGH | 8.7 | Aug 20, 2026 |
| CVE-2026-6956 | Reflected XSS in ATutor | MEDIUM | 5.1 | May 11, 2026 |
| CVE-2026-6909 | Reflected XSS in ATutor | MEDIUM | 5.1 | May 11, 2026 |
| CVE-2020-37147 | ATutor 2.2.4 - 'id' SQL Injection | HIGH | 7.0 | Feb 6, 2026 |
| CVE-2023-27008 | A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to inject arbitrary web… | MEDIUM | 6.1 | Mar 28, 2023 |
| CVE-2021-43498 | An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters a… | HIGH | 7.5 | Apr 8, 2022 |
| CVE-2020-23341 | A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers to execute arbitrary web scripts or HTM… | MEDIUM | 6.1 | Aug 17, 2021 |
| CVE-2015-1583 | Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests tha… | HIGH | 8.8 | Mar 2, 2020 |
| CVE-2014-9753 | confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter. | CRITICAL | 9.8 | Feb 11, 2020 |
| CVE-2019-16114 | In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to t… | CRITICAL | 9.8 | Sep 9, 2019 |
| CVE-2019-12169 | ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/la… | HIGH | 8.8 | Jun 3, 2019 |
| CVE-2019-12170 | ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote command ex… | HIGH | 8.8 | May 17, 2019 |
| CVE-2019-11446 | An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files section in… | HIGH | 8.8 | Apr 22, 2019 |
Showing 1 to 25 of 28 CVEs