Reflected Cross-Site Scripting Vulnerability in Creativeitem Academy LMS
CVE-2025-71179

6.1MEDIUM

Key Information:

Vendor
CVE Published:
3 February 2026

What is CVE-2025-71179?

Creativeitem Academy LMS version 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities that can be exploited via the search parameter on the /academy/blogs endpoint and the string parameter at the /academy/course_bundles/search/query endpoint. These vulnerabilities differ from previous patches, specifically addressing gaps left unmitigated by the earlier fix for related XSS issues. Proper validation and sanitization of user inputs are crucial for mitigating potential security risks associated with these flaws.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.