15 Total CVEs
15 AI Analyzed
0 CISA KEV
5 Critical

Profile

0% ended up actively exploited 0 of 15 added to CISA KEV
33% rated critical (CVSS 9.0+) 5 critical, 10 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

13 CVEs in the last 12 months

Products

  • Kirki3
  • Tutor LMS Pro3
  • Tutor LMS3
  • Kirki Plugin1

4 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-15 of 15 CVEs
CVE-2026-8206
Analyzed
9.8
Themeum Kirki Plugin

The Kirki plugin for WordPress is vulnerable to unauthenticated privilege escalation via an account takeover flaw in the password reset process.

2026-06-02
Full analysis →
CVE-2026-8073
Analyzed
7.5
Themeum

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file...

2026-05-20
Full analysis →
CVE-2026-78175
Analyzed
8.8
Themeum

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,...

2026-09-12
Full analysis →
CVE-2026-57727
Analyzed
7.5
Themeum Kirki

Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels

2026-07-14
Full analysis →
CVE-2026-57726
Analyzed
9.3
Themeum Kirki

Themeum Kirki is susceptible to a Blind SQL Injection vulnerability, allowing unauthenticated attackers to manipulate SQL queries.

2026-07-14
Full analysis →
CVE-2026-57724
Analyzed
9.8
Themeum Kirki

A deserialization of untrusted data vulnerability in the Themeum Kirki WordPress plugin allows for PHP object injection.

2026-07-14
Full analysis →
CVE-2026-3360
Analyzed
7.5
Themeum

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Reference in all versions up to,...

2026-04-11
Full analysis →
CVE-2026-25406
Analyzed
8.8
Themeum Tutor LMS Pro

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse

2026-03-27
Full analysis →
CVE-2026-19092
Analyzed
9.8
Themeum Tutor LMS

The Tutor LMS WordPress plugin before 4.0.6 is vulnerable to an injection flaw allowing unauthenticated users to execute arbitrary zero-argument PHP f...

2026-08-28
Full analysis →
CVE-2026-1375
Analyzed
8.1
Themeum

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions up...

2026-02-03
Full analysis →
CVE-2026-12275
Analyzed
7.1
Themeum Tutor LMS

The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private...

2026-07-16
Full analysis →
CVE-2026-0953
Analyzed
9.8
Themeum Tutor LMS Pro

An authentication bypass in the Tutor LMS Pro plugin for WordPress allows unauthenticated attackers to log in as any user, including administrators, v...

2026-03-11
Full analysis →
CVE-2025-6184
Analyzed
8.8
Themeum Tutor LMS Pro

The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter used...

2025-08-13
Full analysis →
CVE-2025-58993
Analyzed
7.6
Themeum Tutor LMS

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection

2025-09-09
Full analysis →
CVE-2025-13673
Analyzed
7.5
Themeum

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versio...

2026-02-28
Full analysis →