CVE-2025-56747: Creativeitem Academy Lms
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instructor-only functions without proper role validation, allowing unauthorized course creation and management.
Affected products
- Creativeitem Academy Lms: up to and including 5.13
Published 2025-10-14. Last modified 2026-06-17.