Creativeitem kayıtları
creativeitem üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-798 Use of Hard-coded Credentials1
- CWE-269 Improper Privilege Management1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2023-4974Kavram kanıtı | Academy LMS GET Parameter filter sql injectioncreativeitem · academy lms · CWE-89 | Kritik9,8 | — | %5,3 | 14 Eyl 2023 |
37İzleyin | CVE-2025-56749İstismar yok | Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing.creativeitem · academy lms · CWE-798 | Kritik9,4 | — | %0,5 | 15 Eki 2025 |
35İzleyin | CVE-2022-47132Kavram kanıtı | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.creativeitem · academy lms · CWE-352 | Yüksek8,8 | — | %0,9 | 2 Şub 2023 |
26İzleyin | CVE-2020-22273İstismar yok | Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settingcreativeitem · neoflex video subscription system · CWE-352 | Orta6,5 | — | %0,4 | 4 Kas 2020 |
26İzleyin | CVE-2025-56747İstismar yok | Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regulcreativeitem · academy lms · CWE-269 | Orta6,5 | — | %0,3 | 14 Eki 2025 |
25İzleyin | CVE-2023-4119Kavram kanıtı | Academy LMS courses cross site scriptingcreativeitem · academy lms · CWE-79 | Orta6,1 | — | %3,8 | 3 Ağu 2023 |
25İzleyin | CVE-2022-38553Kavram kanıtı | Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Searcreativeitem · academy learning management system · CWE-79 | Orta6,1 | — | %3,0 | 26 Eyl 2022 |
25İzleyin | CVE-2023-4973Kavram kanıtı | Academy LMS GET Parameter filter cross site scriptingcreativeitem · academy lms · CWE-79 | Orta6,1 | — | %1,9 | 14 Eyl 2023 |
25İzleyin | CVE-2025-56748İstismar yok | Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limicreativeitem · academy lms · CWE-640 | Orta6,4 | — | %0,2 | 15 Eki 2025 |
24İzleyin | CVE-2023-38964Kavram kanıtı | Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.creativeitem · academy lms · CWE-79 | Orta6,1 | — | %1,1 | 4 Ağu 2023 |
24İzleyin | CVE-2024-38959İstismar yok | Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attacker to execute arbitrcreativeitem · academy lms · CWE-79 | Orta6,1 | — | %0,7 | 9 Tem 2024 |
24İzleyin | CVE-2023-3754İstismar yok | Creativeitem Ekushey Project Manager CRM xxxxxxxx[random-msg-hash] cross site scriptingcreativeitem · ekushey project manager · CWE-79 | Orta6,1 | — | %0,4 | 18 Tem 2023 |
24İzleyin | CVE-2023-3756İstismar yok | Creativeitem Atlas Business Directory Listing search cross site scriptingcreativeitem · atlas · CWE-79 | Orta6,1 | — | %0,4 | 19 Tem 2023 |
24İzleyin | CVE-2023-3755İstismar yok | Creativeitem Atlas Business Directory Listing filter_listings cross site scriptingcreativeitem · atlas · CWE-79 | Orta6,1 | — | %0,4 | 19 Tem 2023 |
24İzleyin | CVE-2023-3753İstismar yok | Creativeitem Mastery LMS browse cross site scriptingcreativeitem · mastery lms · CWE-79 | Orta6,1 | — | %0,4 | 18 Tem 2023 |
24İzleyin | CVE-2023-3752İstismar yok | Creativeitem Academy LMS courses cross site scriptingcreativeitem · academy lms · CWE-79 | Orta6,1 | — | %0,4 | 18 Tem 2023 |
24İzleyin | CVE-2025-71179İstismar yok | Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs encreativeitem · academy lms · CWE-79 | Orta6,1 | — | %0,3 | 3 Şub 2026 |
21İzleyin | CVE-2018-18417Kavram kanıtı | In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the ncreativeitem · ekushey project manager · CWE-79 | Orta5,4 | — | %1,6 | 19 Eki 2018 |
20İzleyin | CVE-2023-53876İstismar yok | Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settingscreativeitem · academy lms · CWE-434 | Orta5,1 | — | %0,2 | 15 Ara 2025 |
20İzleyin | CVE-2025-40991İstismar yok | Stored XSS in Creativeitem Ekushey CRMcreativeitem · ekushey project manager crm · CWE-79 | Orta5,1 | — | %0,2 | 2 Eki 2025 |
20İzleyin | CVE-2025-40989İstismar yok | Stored XSS in Creativeitem Ekushey CRMcreativeitem · ekushey project manager crm · CWE-79 | Orta5,1 | — | %0,2 | 2 Eki 2025 |
20İzleyin | CVE-2025-40990İstismar yok | Stored XSS in Creativeitem Ekushey CRMcreativeitem · ekushey project manager crm · CWE-79 | Orta5,1 | — | %0,2 | 2 Eki 2025 |
19İzleyin | CVE-2022-29380Kavram kanıtı | Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.creativeitem · academy lms · CWE-79 | Orta4,8 | — | %0,6 | 25 May 2022 |
19İzleyin | CVE-2022-47131Kavram kanıtı | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.creativeitem · academy lms · CWE-79 | Orta4,8 | — | %0,4 | 2 Şub 2023 |
17İzleyin | CVE-2022-47130Kavram kanıtı | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with admincreativeitem · academy lms · CWE-352 | Orta4,3 | — | %0,6 | 2 Şub 2023 |
- CVE-2023-497441Planlayın
Academy LMS GET Parameter filter sql injection
KritikCVSS 9,8Kavram kanıtıEPSS %5creativeitem · academy lms14 Eyl 2023
- CVE-2025-5674937İzleyin
Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing.
KritikCVSS 9,4İstismar yokEPSS %0creativeitem · academy lms15 Eki 2025
- CVE-2022-4713235İzleyin
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.
YüksekCVSS 8,8Kavram kanıtıEPSS %1creativeitem · academy lms2 Şub 2023
- CVE-2020-2227326İzleyin
Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Setting
OrtaCVSS 6,5İstismar yokEPSS %0creativeitem · neoflex video subscription system4 Kas 2020
- CVE-2025-5674726İzleyin
Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regul
OrtaCVSS 6,5İstismar yokEPSS %0creativeitem · academy lms14 Eki 2025
- CVE-2023-411925İzleyin
Academy LMS courses cross site scripting
OrtaCVSS 6,1Kavram kanıtıEPSS %4creativeitem · academy lms3 Ağu 2023
- CVE-2022-3855325İzleyin
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Sear
OrtaCVSS 6,1Kavram kanıtıEPSS %3creativeitem · academy learning management system26 Eyl 2022
- CVE-2023-497325İzleyin
Academy LMS GET Parameter filter cross site scripting
OrtaCVSS 6,1Kavram kanıtıEPSS %2creativeitem · academy lms14 Eyl 2023
- CVE-2025-5674825İzleyin
Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limi
OrtaCVSS 6,4İstismar yokEPSS %0creativeitem · academy lms15 Eki 2025
- CVE-2023-3896424İzleyin
Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
OrtaCVSS 6,1Kavram kanıtıEPSS %1creativeitem · academy lms4 Ağu 2023
- CVE-2024-3895924İzleyin
Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attacker to execute arbitr
OrtaCVSS 6,1İstismar yokEPSS %1creativeitem · academy lms9 Tem 2024
- CVE-2023-375424İzleyin
Creativeitem Ekushey Project Manager CRM xxxxxxxx[random-msg-hash] cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %0creativeitem · ekushey project manager18 Tem 2023
- CVE-2023-375624İzleyin
Creativeitem Atlas Business Directory Listing search cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %0creativeitem · atlas19 Tem 2023
- CVE-2023-375524İzleyin
Creativeitem Atlas Business Directory Listing filter_listings cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %0creativeitem · atlas19 Tem 2023
- CVE-2023-375324İzleyin
Creativeitem Mastery LMS browse cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %0creativeitem · mastery lms18 Tem 2023
- CVE-2023-375224İzleyin
Creativeitem Academy LMS courses cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %0creativeitem · academy lms18 Tem 2023
- CVE-2025-7117924İzleyin
Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs en
OrtaCVSS 6,1İstismar yokEPSS %0creativeitem · academy lms3 Şub 2026
- CVE-2018-1841721İzleyin
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the n
OrtaCVSS 5,4Kavram kanıtıEPSS %2creativeitem · ekushey project manager19 Eki 2018
- CVE-2023-5387620İzleyin
Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings
OrtaCVSS 5,1İstismar yokEPSS %0creativeitem · academy lms15 Ara 2025
- CVE-2025-4099120İzleyin
Stored XSS in Creativeitem Ekushey CRM
OrtaCVSS 5,1İstismar yokEPSS %0creativeitem · ekushey project manager crm2 Eki 2025
- CVE-2025-4098920İzleyin
Stored XSS in Creativeitem Ekushey CRM
OrtaCVSS 5,1İstismar yokEPSS %0creativeitem · ekushey project manager crm2 Eki 2025
- CVE-2025-4099020İzleyin
Stored XSS in Creativeitem Ekushey CRM
OrtaCVSS 5,1İstismar yokEPSS %0creativeitem · ekushey project manager crm2 Eki 2025
- CVE-2022-2938019İzleyin
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
OrtaCVSS 4,8Kavram kanıtıEPSS %1creativeitem · academy lms25 May 2022
- CVE-2022-4713119İzleyin
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.
OrtaCVSS 4,8Kavram kanıtıEPSS %0creativeitem · academy lms2 Şub 2023
- CVE-2022-4713017İzleyin
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with admin
OrtaCVSS 4,3Kavram kanıtıEPSS %1creativeitem · academy lms2 Şub 2023