CVE-2025-56749: Creativeitem Academy Lms
Critical severity, CVSS 9.4. EPSS: 0.5% chance of exploitation in the next 30 days.
Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.
Affected products
- Creativeitem Academy Lms: up to and including 6.14
Published 2025-10-15. Last modified 2026-06-17.