CVE-2025-56746: Creativeitem Academy Lms

Low severity, CVSS 2.2. EPSS: 0.2% chance of exploitation in the next 30 days.

Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.

Affected products

Published 2025-10-15. Last modified 2026-06-17.