Creativeitem develops educational and project-management platforms, including learning management systems and CRM tools that serve academic and organizational workflows. While the vendor's product portfolio is narrow, its disclosures sit within a top-decile prominence band, reflecting the widespread deployment of these platforms in institutional settings. Vulnerabilities affecting the vendor span a meaningful share of serious severity and frequently acquire public exploit code; the recurring exposure centers on web-application input-handling and session-management weaknesses—cross-site scripting, SQL injection, CSRF, and session fixation—alongside improper privilege controls that are characteristic of web platforms handling user authentication and data access. Defenders should prioritize patches for these platforms given their institutional reach and the availability of public exploit tooling; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Creativeitem over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4974CRITICAL A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component | Sep 15, 2023 | 9.8 | 40 | NO | YES |
CVE-2022-38553MEDIUM Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter. | Sep 26, 2022 | 6.1 | 35 | NO | YES |
CVE-2023-4119MEDIUM A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code of the file /academy/home/courses. The manipulation of the | Aug 3, 2023 | 6.1 | 30 | NO | YES |
CVE-2018-18417MEDIUM In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/cli | Oct 19, 2018 | 5.4 | 30 | NO | YES |
CVE-2025-56749CRITICAL Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading | Oct 15, 2025 | 9.4 | 29 | NO | NO |
CVE-2023-4973MEDIUM A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/ | Sep 15, 2023 | 6.1 | 28 | NO | YES |
CVE-2023-38964MEDIUM Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability. | Aug 4, 2023 | 6.1 | 27 | NO | YES |
CVE-2022-47132HIGH A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users. | Feb 3, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-56748MEDIUM Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to gu | Oct 15, 2025 | 6.4 | 22 | NO | NO |
CVE-2025-56747MEDIUM Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instru | Oct 14, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Creativeitem.
Media articles that mention a CVE ID that affects a product developed by Creativeitem — matched by CVE ID, not by vendor name.