Записи Creativeitem
26 опубликованных записей вендора creativeitem.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-798 Use of Hard-coded Credentials1
- CWE-269 Improper Privilege Management1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2023-4974Proof of concept | Academy LMS GET Parameter filter sql injectioncreativeitem · academy lms · CWE-89 | Критическая9,8 | — | 5,3 % | 14 сент. 2023 г. |
37Наблюдать | CVE-2025-56749Эксплойта нет | Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing.creativeitem · academy lms · CWE-798 | Критическая9,4 | — | 0,5 % | 15 окт. 2025 г. |
35Наблюдать | CVE-2022-47132Proof of concept | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.creativeitem · academy lms · CWE-352 | Высокая8,8 | — | 0,9 % | 2 февр. 2023 г. |
26Наблюдать | CVE-2020-22273Эксплойта нет | Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settingcreativeitem · neoflex video subscription system · CWE-352 | Средняя6,5 | — | 0,4 % | 4 нояб. 2020 г. |
26Наблюдать | CVE-2025-56747Эксплойта нет | Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regulcreativeitem · academy lms · CWE-269 | Средняя6,5 | — | 0,3 % | 14 окт. 2025 г. |
25Наблюдать | CVE-2023-4119Proof of concept | Academy LMS courses cross site scriptingcreativeitem · academy lms · CWE-79 | Средняя6,1 | — | 3,8 % | 3 авг. 2023 г. |
25Наблюдать | CVE-2022-38553Proof of concept | Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Searcreativeitem · academy learning management system · CWE-79 | Средняя6,1 | — | 3,0 % | 26 сент. 2022 г. |
25Наблюдать | CVE-2023-4973Proof of concept | Academy LMS GET Parameter filter cross site scriptingcreativeitem · academy lms · CWE-79 | Средняя6,1 | — | 1,9 % | 14 сент. 2023 г. |
25Наблюдать | CVE-2025-56748Эксплойта нет | Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limicreativeitem · academy lms · CWE-640 | Средняя6,4 | — | 0,2 % | 15 окт. 2025 г. |
24Наблюдать | CVE-2023-38964Proof of concept | Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.creativeitem · academy lms · CWE-79 | Средняя6,1 | — | 1,1 % | 4 авг. 2023 г. |
24Наблюдать | CVE-2024-38959Эксплойта нет | Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attacker to execute arbitrcreativeitem · academy lms · CWE-79 | Средняя6,1 | — | 0,7 % | 9 июл. 2024 г. |
24Наблюдать | CVE-2023-3754Эксплойта нет | Creativeitem Ekushey Project Manager CRM xxxxxxxx[random-msg-hash] cross site scriptingcreativeitem · ekushey project manager · CWE-79 | Средняя6,1 | — | 0,4 % | 18 июл. 2023 г. |
24Наблюдать | CVE-2023-3756Эксплойта нет | Creativeitem Atlas Business Directory Listing search cross site scriptingcreativeitem · atlas · CWE-79 | Средняя6,1 | — | 0,4 % | 19 июл. 2023 г. |
24Наблюдать | CVE-2023-3755Эксплойта нет | Creativeitem Atlas Business Directory Listing filter_listings cross site scriptingcreativeitem · atlas · CWE-79 | Средняя6,1 | — | 0,4 % | 19 июл. 2023 г. |
24Наблюдать | CVE-2023-3753Эксплойта нет | Creativeitem Mastery LMS browse cross site scriptingcreativeitem · mastery lms · CWE-79 | Средняя6,1 | — | 0,4 % | 18 июл. 2023 г. |
24Наблюдать | CVE-2023-3752Эксплойта нет | Creativeitem Academy LMS courses cross site scriptingcreativeitem · academy lms · CWE-79 | Средняя6,1 | — | 0,4 % | 18 июл. 2023 г. |
24Наблюдать | CVE-2025-71179Эксплойта нет | Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs encreativeitem · academy lms · CWE-79 | Средняя6,1 | — | 0,3 % | 3 февр. 2026 г. |
21Наблюдать | CVE-2018-18417Proof of concept | In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the ncreativeitem · ekushey project manager · CWE-79 | Средняя5,4 | — | 1,6 % | 19 окт. 2018 г. |
20Наблюдать | CVE-2023-53876Эксплойта нет | Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settingscreativeitem · academy lms · CWE-434 | Средняя5,1 | — | 0,2 % | 15 дек. 2025 г. |
20Наблюдать | CVE-2025-40991Эксплойта нет | Stored XSS in Creativeitem Ekushey CRMcreativeitem · ekushey project manager crm · CWE-79 | Средняя5,1 | — | 0,2 % | 2 окт. 2025 г. |
20Наблюдать | CVE-2025-40989Эксплойта нет | Stored XSS in Creativeitem Ekushey CRMcreativeitem · ekushey project manager crm · CWE-79 | Средняя5,1 | — | 0,2 % | 2 окт. 2025 г. |
20Наблюдать | CVE-2025-40990Эксплойта нет | Stored XSS in Creativeitem Ekushey CRMcreativeitem · ekushey project manager crm · CWE-79 | Средняя5,1 | — | 0,2 % | 2 окт. 2025 г. |
19Наблюдать | CVE-2022-29380Proof of concept | Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.creativeitem · academy lms · CWE-79 | Средняя4,8 | — | 0,6 % | 25 мая 2022 г. |
19Наблюдать | CVE-2022-47131Proof of concept | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.creativeitem · academy lms · CWE-79 | Средняя4,8 | — | 0,4 % | 2 февр. 2023 г. |
17Наблюдать | CVE-2022-47130Proof of concept | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with admincreativeitem · academy lms · CWE-352 | Средняя4,3 | — | 0,6 % | 2 февр. 2023 г. |
- CVE-2023-497441В плане
Academy LMS GET Parameter filter sql injection
КритическаяCVSS 9,8Proof of conceptEPSS 5 %creativeitem · academy lms14 сент. 2023 г.
- CVE-2025-5674937Наблюдать
Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing.
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %creativeitem · academy lms15 окт. 2025 г.
- CVE-2022-4713235Наблюдать
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %creativeitem · academy lms2 февр. 2023 г.
- CVE-2020-2227326Наблюдать
Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Setting
СредняяCVSS 6,5Эксплойта нетEPSS 0 %creativeitem · neoflex video subscription system4 нояб. 2020 г.
- CVE-2025-5674726Наблюдать
Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regul
СредняяCVSS 6,5Эксплойта нетEPSS 0 %creativeitem · academy lms14 окт. 2025 г.
- CVE-2023-411925Наблюдать
Academy LMS courses cross site scripting
СредняяCVSS 6,1Proof of conceptEPSS 4 %creativeitem · academy lms3 авг. 2023 г.
- CVE-2022-3855325Наблюдать
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Sear
СредняяCVSS 6,1Proof of conceptEPSS 3 %creativeitem · academy learning management system26 сент. 2022 г.
- CVE-2023-497325Наблюдать
Academy LMS GET Parameter filter cross site scripting
СредняяCVSS 6,1Proof of conceptEPSS 2 %creativeitem · academy lms14 сент. 2023 г.
- CVE-2025-5674825Наблюдать
Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limi
СредняяCVSS 6,4Эксплойта нетEPSS 0 %creativeitem · academy lms15 окт. 2025 г.
- CVE-2023-3896424Наблюдать
Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
СредняяCVSS 6,1Proof of conceptEPSS 1 %creativeitem · academy lms4 авг. 2023 г.
- CVE-2024-3895924Наблюдать
Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attacker to execute arbitr
СредняяCVSS 6,1Эксплойта нетEPSS 1 %creativeitem · academy lms9 июл. 2024 г.
- CVE-2023-375424Наблюдать
Creativeitem Ekushey Project Manager CRM xxxxxxxx[random-msg-hash] cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 0 %creativeitem · ekushey project manager18 июл. 2023 г.
- CVE-2023-375624Наблюдать
Creativeitem Atlas Business Directory Listing search cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 0 %creativeitem · atlas19 июл. 2023 г.
- CVE-2023-375524Наблюдать
Creativeitem Atlas Business Directory Listing filter_listings cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 0 %creativeitem · atlas19 июл. 2023 г.
- CVE-2023-375324Наблюдать
Creativeitem Mastery LMS browse cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 0 %creativeitem · mastery lms18 июл. 2023 г.
- CVE-2023-375224Наблюдать
Creativeitem Academy LMS courses cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 0 %creativeitem · academy lms18 июл. 2023 г.
- CVE-2025-7117924Наблюдать
Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs en
СредняяCVSS 6,1Эксплойта нетEPSS 0 %creativeitem · academy lms3 февр. 2026 г.
- CVE-2018-1841721Наблюдать
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the n
СредняяCVSS 5,4Proof of conceptEPSS 2 %creativeitem · ekushey project manager19 окт. 2018 г.
- CVE-2023-5387620Наблюдать
Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings
СредняяCVSS 5,1Эксплойта нетEPSS 0 %creativeitem · academy lms15 дек. 2025 г.
- CVE-2025-4099120Наблюдать
Stored XSS in Creativeitem Ekushey CRM
СредняяCVSS 5,1Эксплойта нетEPSS 0 %creativeitem · ekushey project manager crm2 окт. 2025 г.
- CVE-2025-4098920Наблюдать
Stored XSS in Creativeitem Ekushey CRM
СредняяCVSS 5,1Эксплойта нетEPSS 0 %creativeitem · ekushey project manager crm2 окт. 2025 г.
- CVE-2025-4099020Наблюдать
Stored XSS in Creativeitem Ekushey CRM
СредняяCVSS 5,1Эксплойта нетEPSS 0 %creativeitem · ekushey project manager crm2 окт. 2025 г.
- CVE-2022-2938019Наблюдать
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
СредняяCVSS 4,8Proof of conceptEPSS 1 %creativeitem · academy lms25 мая 2022 г.
- CVE-2022-4713119Наблюдать
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.
СредняяCVSS 4,8Proof of conceptEPSS 0 %creativeitem · academy lms2 февр. 2023 г.
- CVE-2022-4713017Наблюдать
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with admin
СредняяCVSS 4,3Proof of conceptEPSS 1 %creativeitem · academy lms2 февр. 2023 г.