Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Creativeitem

First CVE: Oct 19, 2018Active for: 8 yearsTotal CVEs: 26
23.5
VTI Score
Low

Creativeitem develops educational and project-management platforms, including learning management systems and CRM tools that serve academic and organizational workflows. While the vendor's product portfolio is narrow, its disclosures sit within a top-decile prominence band, reflecting the widespread deployment of these platforms in institutional settings. Vulnerabilities affecting the vendor span a meaningful share of serious severity and frequently acquire public exploit code; the recurring exposure centers on web-application input-handling and session-management weaknesses—cross-site scripting, SQL injection, CSRF, and session fixation—alongside improper privilege controls that are characteristic of web platforms handling user authentication and data access. Defenders should prioritize patches for these platforms given their institutional reach and the availability of public exploit tooling; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Creativeitem over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 19, 2018
7 years ago
Most Recent CVE
Feb 3, 2026
171 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-4974CRITICAL
A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component
Sep 15, 20239.840NOYES
CVE-2022-38553MEDIUM
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
Sep 26, 20226.135NOYES
CVE-2023-4119MEDIUM
A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code of the file /academy/home/courses. The manipulation of the
Aug 3, 20236.130NOYES
CVE-2018-18417MEDIUM
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/cli
Oct 19, 20185.430NOYES
CVE-2025-56749CRITICAL
Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading
Oct 15, 20259.429NONO
CVE-2023-4973MEDIUM
A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/
Sep 15, 20236.128NOYES
CVE-2023-38964MEDIUM
Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
Aug 4, 20236.127NOYES
CVE-2022-47132HIGH
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.
Feb 3, 20238.827NONO
CVE-2025-56748MEDIUM
Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to gu
Oct 15, 20256.422NONO
CVE-2025-56747MEDIUM
Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instru
Oct 14, 20256.522NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
85%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (3.8%)
Network25 (96.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (92.3%)
High2 (7.7%)
Unknown0 (0.0%)
User Interaction
None3 (11.5%)
Unknown0 (0.0%)
Required23 (88.5%)
Privileges Required
Low6 (23.1%)
High2 (7.7%)
None18 (69.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
15.4% of CVEs· 97th percentile
ExploitDB
2 CVEs
7.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Creativeitem.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Creativeitem — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Creativeitem's Products

View all 4 CNAs →

Top CWEs