CVE-2025-56746: Creativeitem Academy Lms
Low severity, CVSS 2.2. EPSS: 0.2% chance of exploitation in the next 30 days.
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
Affected products
- Creativeitem Academy Lms: up to and including 5.13
Published 2025-10-15. Last modified 2026-06-17.