İçeriğe atla
Noroxi

Creativeitem kayıtları

creativeitem üreticisine ait 26 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

26 kayıt
  • CVE-2023-4974
    41Planlayın

    Academy LMS GET Parameter filter sql injection

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    creativeitem · academy lms14 Eyl 2023

  • CVE-2025-56749
    37İzleyin

    Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing.

    KritikCVSS 9,4İstismar yokEPSS %0

    creativeitem · academy lms15 Eki 2025

  • CVE-2022-47132
    35İzleyin

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.

    YüksekCVSS 8,8Kavram kanıtıEPSS %1

    creativeitem · academy lms2 Şub 2023

  • CVE-2020-22273
    26İzleyin

    Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Setting

    OrtaCVSS 6,5İstismar yokEPSS %0

    creativeitem · neoflex video subscription system4 Kas 2020

  • CVE-2025-56747
    26İzleyin

    Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regul

    OrtaCVSS 6,5İstismar yokEPSS %0

    creativeitem · academy lms14 Eki 2025

  • CVE-2023-4119
    25İzleyin

    Academy LMS courses cross site scripting

    OrtaCVSS 6,1Kavram kanıtıEPSS %4

    creativeitem · academy lms3 Ağu 2023

  • CVE-2022-38553
    25İzleyin

    Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Sear

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    creativeitem · academy learning management system26 Eyl 2022

  • CVE-2023-4973
    25İzleyin

    Academy LMS GET Parameter filter cross site scripting

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    creativeitem · academy lms14 Eyl 2023

  • CVE-2025-56748
    25İzleyin

    Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limi

    OrtaCVSS 6,4İstismar yokEPSS %0

    creativeitem · academy lms15 Eki 2025

  • CVE-2023-38964
    24İzleyin

    Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    creativeitem · academy lms4 Ağu 2023

  • CVE-2024-38959
    24İzleyin

    Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attacker to execute arbitr

    OrtaCVSS 6,1İstismar yokEPSS %1

    creativeitem · academy lms9 Tem 2024

  • CVE-2023-3754
    24İzleyin

    Creativeitem Ekushey Project Manager CRM xxxxxxxx[random-msg-hash] cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %0

    creativeitem · ekushey project manager18 Tem 2023

  • CVE-2023-3756
    24İzleyin

    Creativeitem Atlas Business Directory Listing search cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %0

    creativeitem · atlas19 Tem 2023

  • CVE-2023-3755
    24İzleyin

    Creativeitem Atlas Business Directory Listing filter_listings cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %0

    creativeitem · atlas19 Tem 2023

  • CVE-2023-3753
    24İzleyin

    Creativeitem Mastery LMS browse cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %0

    creativeitem · mastery lms18 Tem 2023

  • CVE-2023-3752
    24İzleyin

    Creativeitem Academy LMS courses cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %0

    creativeitem · academy lms18 Tem 2023

  • CVE-2025-71179
    24İzleyin

    Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs en

    OrtaCVSS 6,1İstismar yokEPSS %0

    creativeitem · academy lms3 Şub 2026

  • CVE-2018-18417
    21İzleyin

    In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the n

    OrtaCVSS 5,4Kavram kanıtıEPSS %2

    creativeitem · ekushey project manager19 Eki 2018

  • CVE-2023-53876
    20İzleyin

    Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings

    OrtaCVSS 5,1İstismar yokEPSS %0

    creativeitem · academy lms15 Ara 2025

  • CVE-2025-40991
    20İzleyin

    Stored XSS in Creativeitem Ekushey CRM

    OrtaCVSS 5,1İstismar yokEPSS %0

    creativeitem · ekushey project manager crm2 Eki 2025

  • CVE-2025-40989
    20İzleyin

    Stored XSS in Creativeitem Ekushey CRM

    OrtaCVSS 5,1İstismar yokEPSS %0

    creativeitem · ekushey project manager crm2 Eki 2025

  • CVE-2025-40990
    20İzleyin

    Stored XSS in Creativeitem Ekushey CRM

    OrtaCVSS 5,1İstismar yokEPSS %0

    creativeitem · ekushey project manager crm2 Eki 2025

  • CVE-2022-29380
    19İzleyin

    Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.

    OrtaCVSS 4,8Kavram kanıtıEPSS %1

    creativeitem · academy lms25 May 2022

  • CVE-2022-47131
    19İzleyin

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.

    OrtaCVSS 4,8Kavram kanıtıEPSS %0

    creativeitem · academy lms2 Şub 2023

  • CVE-2022-47130
    17İzleyin

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with admin

    OrtaCVSS 4,3Kavram kanıtıEPSS %1

    creativeitem · academy lms2 Şub 2023