creativeitem
Enterprise Softwarecommercial
Latest CVEs
The 15 most recently published vulnerabilities affecting creativeitem.
- CVE-2026-26211Ekushey Project Manager CRM 5.0 Stored XSS via System Name Field4.8
- CVE-2026-66031Ekushey Project Manager CRM 5.0 Stored XSS via Reply Ticket Field5.4
- CVE-2026-66030Ekushey Project Manager CRM 5.0 Stored XSS via Ticket Title Field5.4
- CVE-2026-66029Ekushey Project Manager CRM 5.0 Stored XSS via Client Name Field5.4
- CVE-2026-66028Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email6.7
- CVE-2025-71179Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs endpoint, and the string parameter to the /academy/course_b...6.1
- CVE-2023-53876Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings5.4
- CVE-2025-56746Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by prede...2.2
- CVE-2025-56748Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset t...6.4
- CVE-2025-56749Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authenticatio...9.4
- CVE-2025-56747Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instructor-only functio...6.5
- CVE-2025-40992Stored XSS in Creativeitem Sociopro
- CVE-2025-40991Stored XSS in Creativeitem Ekushey CRM5.4
- CVE-2025-40990Stored XSS in Creativeitem Ekushey CRM5.4
- CVE-2025-40989Stored XSS in Creativeitem Ekushey CRM5.4