Academy Lms

Vendor:

First CVE: May 25, 2022 · Active for 4 years

16
Total CVEs
More Total CVEs than 93% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Academy Lms over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 25, 2022
4 years ago
Most Recent CVE
Feb 3, 2026
175 days ago

CVE Severity & Scoring

Academy Lms16 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local1 (6.3%)
Network15 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (87.5%)
High2 (12.5%)
Unknown0 (0.0%)
User Interaction
None3 (18.8%)
Unknown0 (0.0%)
Required13 (81.3%)
Privileges Required
Low2 (12.5%)
High2 (12.5%)
None12 (75.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component
Sep 15, 20239.840NOYES
A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code of the file /academy/home/courses. The manipulation of the
Aug 3, 20236.130NOYES
Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading
Oct 15, 20259.429NONO
A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/
Sep 15, 20236.128NOYES
Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
Aug 4, 20236.127NOYES
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.
Feb 3, 20238.827NONO
Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to gu
Oct 15, 20256.422NONO
Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instru
Oct 14, 20256.522NONO
Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs endpoint, and the string parameter to the
Feb 3, 20266.121NONO
A vulnerability was found in Creativeitem Academy LMS 5.15. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /home/courses. The ma
Jul 19, 20236.121NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
18.8% of CVEs· 98th percentile
ExploitDB
1 CVE
6.2% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Academy Lms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.016.10.2%00
6.8.116.10.7%00
6.228.03.4%02
6.115.40.2%00
6.026.11.5%02
5.1516.10.4%00
4.314.80.6%00