Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Creativeitem Subscribe
Total 7 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-47132 1 Creativeitem 1 Academy Lms 2023-02-09 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.
CVE-2022-47131 1 Creativeitem 1 Academy Lms 2023-02-09 N/A 4.8 MEDIUM
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.
CVE-2022-47130 1 Creativeitem 1 Academy Lms 2023-02-09 N/A 4.3 MEDIUM
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page.
CVE-2022-38553 1 Creativeitem 1 Academy Learning Management System 2022-09-28 N/A 6.1 MEDIUM
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
CVE-2022-29380 1 Creativeitem 1 Academy Lms 2022-06-02 3.5 LOW 4.8 MEDIUM
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
CVE-2020-22273 1 Creativeitem 1 Neoflex Video Subscription System 2020-11-13 4.3 MEDIUM 6.5 MEDIUM
Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)
CVE-2018-18417 1 Creativeitem 1 Ekushey Project Manager 2018-12-04 3.5 LOW 5.4 MEDIUM
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.