VYPR
Vendor

Cminds

Products
11
CVEs
25
Across products
26
Status
Private

Products

11

Recent CVEs

25
View all 25 CVEs →
  • CVE-2024-1962HigMar 25, 2024
    risk 0.57cvss 8.8epss 0.00

    The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF attack

  • CVE-2023-30750HigDec 20, 2023
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Popup Plugin for WordPress: from n/a through 1.5.10.

  • CVE-2024-5167HigJul 13, 2024
    risk 0.53cvss 8.1epss 0.00

    The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which could allow attackers to make a logged in admin add or delete settings from the blacklist or whitelist…

  • CVE-2020-24146HigJul 7, 2021
    risk 0.53cvss 8.1epss 0.02

    Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.

  • CVE-2022-3076HigSep 26, 2022
    risk 0.47cvss 7.2epss 0.01

    The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.

  • CVE-2024-1231MedMar 25, 2024
    risk 0.44cvss 6.8epss 0.00

    The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack

  • CVE-2024-5028MedJul 13, 2024
    risk 0.42cvss 6.5epss 0.00

    The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

  • CVE-2020-24145MedJul 7, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted deletescreenshot action.

  • CVE-2020-27344MedOct 21, 2020
    risk 0.40cvss 6.1epss 0.01

    The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.

  • CVE-2016-1000132MedOct 10, 2016
    risk 0.40cvss 6.1epss 0.04

    Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8

  • CVE-2023-31228MedAug 18, 2023
    risk 0.38cvss 5.9epss 0.00

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.0 versions.

  • CVE-2023-25992MedMar 23, 2023
    risk 0.38cvss 5.9epss 0.00

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeMindsSolutions CM Answers plugin <= 3.1.9 versions.

  • CVE-2021-24678MedOct 4, 2021
    risk 0.35cvss 5.4epss 0.01

    The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks

  • CVE-2024-5026MedMay 15, 2025
    risk 0.31cvss 4.8epss 0.00

    The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2024-5029MedNov 21, 2024
    risk 0.31cvss 4.8epss 0.00

    The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

  • CVE-2024-5799MedSep 12, 2024
    risk 0.31cvss 4.8epss 0.00

    The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.

  • CVE-2024-5004MedJul 22, 2024
    risk 0.31cvss 4.8epss 0.00

    The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

  • CVE-2024-1232MedMar 25, 2024
    risk 0.31cvss 4.8epss 0.00

    The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete downloads via a CSRF attack

  • CVE-2021-24713MedNov 23, 2021
    risk 0.31cvss 4.8epss 0.01

    The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks

  • CVE-2025-46246MedApr 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Request Forgery.This issue affects CM Answers: from n/a through <= 3.3.3.