Creativeitem
16 CVEs tracked since 2023. Since Feb 2023, none of them reached CISA KEV.
Creativeitem CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-02 | 3 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | 5 | 0 |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | 8 | 0 |
Products
The products that kept showing up in Creativeitem's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Creativeitem.
- CVE-2026-26211Ekushey Project Manager CRM 5.0 Stored XSS via System Name Field4.8
- CVE-2026-66031Ekushey Project Manager CRM 5.0 Stored XSS via Reply Ticket Field5.4
- CVE-2026-66030Ekushey Project Manager CRM 5.0 Stored XSS via Ticket Title Field5.4
- CVE-2026-66029Ekushey Project Manager CRM 5.0 Stored XSS via Client Name Field5.4
- CVE-2026-66028Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email6.7
- CVE-2025-71179Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs endpoint, and the string parameter to the /academy/course_b...6.1
- CVE-2023-53876Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings5.4
- CVE-2025-56746Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by prede...2.2
- CVE-2025-56748Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset t...6.4
- CVE-2025-56749Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authenticatio...9.4
- CVE-2025-56747Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instructor-only functio...6.5
- CVE-2025-40992Stored XSS in Creativeitem Sociopro—
- CVE-2025-40991Stored XSS in Creativeitem Ekushey CRM5.4
- CVE-2025-40990Stored XSS in Creativeitem Ekushey CRM5.4
- CVE-2025-40989Stored XSS in Creativeitem Ekushey CRM5.4
The record
- Peak rank
- #122 in Oct 2025
- Busiest month shown
- Oct 2025, 8 CVEs
- Months with a KEV entry
- 0 since Feb 2023
- Monthly snapshots
- 3 since 2023