Creativeitem
creativeitem
26 CVEs • 7 products
Products (7)
Click to collapseToggle
Products (7)
Click to collapse
CVEs (26)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page. |
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page. |
1Creativeitem 1Academy Learning Management System Jul 9, 2026 Sep 26, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter. |
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel. |
1Creativeitem 1Neoflex Video Subscription System Jun 17, 2026 Nov 4, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings) |
1Creativeitem 1Ekushey Project Manager Nov 21, 2024 Oct 19, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI. |