CVE-2025-71179

Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs endpoint, and the string parameter to the /academy/course_bundles/search/query endpoint. These vulnerabilities are distinct from the patch for CVE-2023-4119, which only fixed XSS in query and sort_by parameters to the /academy/home/courses endpoint.
Configurations

Configuration 1 (hide)

cpe:2.3:a:creativeitem:academy_lms:7.0:*:*:*:*:*:*:*

History

10 Feb 2026, 14:02

Type Values Removed Values Added
References () https://codecanyon.net/item/academy-course-based-learning-management-system/22703468 - () https://codecanyon.net/item/academy-course-based-learning-management-system/22703468 - Product
References () https://creativeitem.com/products/academy-learning-management-system/ - () https://creativeitem.com/products/academy-learning-management-system/ - Broken Link
References () https://github.com/cod3rLucas/security-advisories/blob/main/CVE-2025-71179.md - () https://github.com/cod3rLucas/security-advisories/blob/main/CVE-2025-71179.md - Exploit, Third Party Advisory
References () https://www.exploit-db.com/exploits/51654 - () https://www.exploit-db.com/exploits/51654 - Exploit, Third Party Advisory
First Time Creativeitem
Creativeitem academy Lms
CPE cpe:2.3:a:creativeitem:academy_lms:7.0:*:*:*:*:*:*:*

04 Feb 2026, 20:16

Type Values Removed Values Added
References
  • {'url': 'https://nvd.nist.gov/vuln/detail/CVE-2023-4119', 'source': 'cve@mitre.org'}
  • () https://github.com/cod3rLucas/security-advisories/blob/main/CVE-2025-71179.md -

04 Feb 2026, 17:16

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://www.exploit-db.com/exploits/51654 - () https://www.exploit-db.com/exploits/51654 -

03 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 18:16

Updated : 2026-02-10 14:02


NVD link : CVE-2025-71179

Mitre link : CVE-2025-71179

CVE.ORG link : CVE-2025-71179


JSON object : View

Products Affected

creativeitem

  • academy_lms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')