Vulnerabilities (CVE)

Filtered by vendor Creativeitem Subscribe
Total 24 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-47132 1 Creativeitem 1 Academy Lms 2024-11-21 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.
CVE-2022-29380 1 Creativeitem 1 Academy Lms 2024-11-21 3.5 LOW 4.8 MEDIUM
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
CVE-2020-22273 1 Creativeitem 1 Neoflex Video Subscription System 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)
CVE-2018-18417 1 Creativeitem 1 Ekushey Project Manager 2024-11-21 3.5 LOW 5.4 MEDIUM
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.