Academy Lms
Vendor:
First CVE: May 25, 2022 · Active for 4 years
16
Total CVEs
More Total CVEs than 93% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Academy Lms over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 25, 2022
4 years ago
Most Recent CVE
Feb 3, 2026
175 days ago
CVE Severity & Scoring
Academy Lms16 CVEs
75%
13%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (6.3%)
Network15 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (87.5%)
High2 (12.5%)
Unknown0 (0.0%)
User Interaction
None3 (18.8%)
Unknown0 (0.0%)
Required13 (81.3%)
Privileges Required
Low2 (12.5%)
High2 (12.5%)
None12 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4974CRITICAL A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component | Sep 15, 2023 | 9.8 | 40 | NO | YES |
CVE-2023-4119MEDIUM A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code of the file /academy/home/courses. The manipulation of the | Aug 3, 2023 | 6.1 | 30 | NO | YES |
CVE-2025-56749CRITICAL Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading | Oct 15, 2025 | 9.4 | 29 | NO | NO |
CVE-2023-4973MEDIUM A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/ | Sep 15, 2023 | 6.1 | 28 | NO | YES |
CVE-2023-38964MEDIUM Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability. | Aug 4, 2023 | 6.1 | 27 | NO | YES |
CVE-2022-47132HIGH A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users. | Feb 3, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-56748MEDIUM Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to gu | Oct 15, 2025 | 6.4 | 22 | NO | NO |
CVE-2025-56747MEDIUM Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instru | Oct 14, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-71179MEDIUM Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs endpoint, and the string parameter to the | Feb 3, 2026 | 6.1 | 21 | NO | NO |
CVE-2023-3752MEDIUM A vulnerability was found in Creativeitem Academy LMS 5.15. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /home/courses. The ma | Jul 19, 2023 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
18.8% of CVEs· 98th percentile
ExploitDB
1 CVE
6.2% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Academy Lms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0 | 1 | 6.1 | 0.2% | 0 | 0 |
| 6.8.1 | 1 | 6.1 | 0.7% | 0 | 0 |
| 6.2 | 2 | 8.0 | 3.4% | 0 | 2 |
| 6.1 | 1 | 5.4 | 0.2% | 0 | 0 |
| 6.0 | 2 | 6.1 | 1.5% | 0 | 2 |
| 5.15 | 1 | 6.1 | 0.4% | 0 | 0 |
| 4.3 | 1 | 4.8 | 0.6% | 0 | 0 |