cminds records
24 published records for vendor cminds.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-1962No exploit | CM Download and File Manager < 2.9.1 - Download Edit via CSRFcminds · cm download manager · CWE-352 | High8.8 | — | 0.5% | Mar 25, 2024 |
35Monitor | CVE-2023-28749No exploit | WordPress CM On Demand Search And Replace Plugin <= 1.3.0 is vulnerable to Cross Site Request Forgery (CSRF)cminds · cm search and replace · CWE-352 | High8.8 | — | 0.3% | Nov 22, 2023 |
35Monitor | CVE-2025-46246No exploit | WordPress CM Answers plugin <= 3.3.3 - Cross Site Request Forgery (CSRF) Vulnerabilitycminds · cm answers · CWE-352 | High8.8 | — | 0.2% | Apr 22, 2025 |
35Monitor | CVE-2025-46245No exploit | WordPress CM Ad Changer plugin <= 2.0.5 - Cross Site Request Forgery (CSRF) Vulnerabilitycminds · cm ad changer · CWE-352 | High8.8 | — | 0.2% | Apr 22, 2025 |
33Monitor | CVE-2020-24146No exploit | Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrcminds · cm download manager · CWE-22 | High8.1 | — | 1.7% | Jul 7, 2021 |
32Monitor | CVE-2023-30750No exploit | WordPress CM Pop-Up banners Plugin <= 1.5.10 is vulnerable to SQL Injectioncminds · cm popup · CWE-89 | High8.1 | — | 0.6% | Dec 20, 2023 |
32Monitor | CVE-2024-5167No exploit | CM Email Registration Blacklist and Whitelist < 1.4.9 - Add/Delete Emails via CSRF Add and delete any item from blacklist/whitelistcminds · cm e-mail blacklist · CWE-352 | High8.1 | — | 0.3% | Jul 13, 2024 |
28Monitor | CVE-2022-3076No exploit | CM Download Manager < 2.8.6 - Admin+ Arbitrary File Uploadcminds · cm download manager · CWE-434 | High7.2 | — | 1.5% | Sep 26, 2022 |
27Monitor | CVE-2014-9129No exploit | Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote atcminds · cm download manager · CWE-352 | Medium6.8 | — | 1.5% | Dec 5, 2014 |
27Monitor | CVE-2024-1231No exploit | CM Download and File Manager < 2.9.0 - Download Unpublish via CSRFcminds · cm download manager · CWE-352 | Medium6.8 | — | 0.2% | Mar 25, 2024 |
26Monitor | CVE-2024-5028No exploit | CM WordPress Search And Replace Plugin < 1.3.9 - Plugin Reset via CSRFcminds · cm search and replace · CWE-352 | Medium6.5 | — | 0.2% | Jul 13, 2024 |
25Monitor | CVE-2016-1000132Proof of concept | Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8cminds · tooltip glossary · CWE-79 | Medium6.1 | — | 4.4% | Oct 10, 2016 |
24Monitor | CVE-2020-27344No exploit | The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.cminds · cm download manager · CWE-79 | Medium6.1 | — | 1.0% | Oct 21, 2020 |
24Monitor | CVE-2020-24145No exploit | Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attaccminds · cm download manager · CWE-79 | Medium6.1 | — | 1.0% | Jul 7, 2021 |
21Monitor | CVE-2021-24678No exploit | CM Tooltip Glossary < 3.9.21 - Contributor+ Stored Cross-Site Scriptingcminds · tooltip glossary · CWE-79 | Medium5.4 | — | 0.6% | Oct 4, 2021 |
19Monitor | CVE-2021-24713No exploit | Video Lessons Manager - Admin+ Stored Cross-Site Scriptingcminds · video lessons manager · CWE-79 | Medium4.8 | — | 0.6% | Nov 23, 2021 |
19Monitor | CVE-2023-25992No exploit | WordPress CM Answers Plugin <= 3.1.9 is vulnerable to Cross Site Scripting (XSS)cminds · cm answers · CWE-79 | Medium4.8 | — | 0.4% | Mar 23, 2023 |
19Monitor | CVE-2023-31228No exploit | WordPress CM On Demand Search And Replace Plugin <= 1.3.0 is vulnerable to Cross Site Scripting (XSS)cminds · cm search and replace · CWE-79 | Medium4.8 | — | 0.4% | Aug 18, 2023 |
19Monitor | CVE-2024-5004No exploit | CM Popup Plugin for WordPress < 1.6.6 - Contributor+ Stored XSScminds · cm popup · CWE-79 | Medium4.8 | — | 0.3% | Jul 22, 2024 |
19Monitor | CVE-2024-5799No exploit | CM Pop-Up Banners for WordPress < 1.7.3 - Contributor+ Stored XSScminds · cm popup · CWE-79 | Medium4.8 | — | 0.3% | Sep 12, 2024 |
19Monitor | CVE-2024-5026No exploit | CM Tooltip Glossary < 4.3.4 - Admin+ Stored XSScminds · cm tooltip glossary · CWE-79 | Medium4.8 | — | 0.3% | May 15, 2025 |
19Monitor | CVE-2024-1232No exploit | CM Download Manager < 2.9.0 - Download Deletion via CSRFcminds · cm download manager · CWE-352 | Medium4.8 | — | 0.2% | Mar 25, 2024 |
19Monitor | CVE-2024-5029No exploit | CM Table Of Contents – WordPress TOC Plugin < 1.2.4 - Stored XSS via CSRFcminds · cm table of contents · CWE-352 | Medium4.8 | — | 0.2% | Nov 21, 2024 |
15Monitor | CVE-2024-5030No exploit | CM Table Of Contents – WordPress TOC Plugin < 1.2.3 - Settings Reset via CSRFcminds · cm table of contents · CWE-352 | Low3.8 | — | 0.2% | Nov 18, 2024 |
- CVE-2024-196235Monitor
CM Download and File Manager < 2.9.1 - Download Edit via CSRF
HighCVSS 8.8No exploitEPSS 0%cminds · cm download managerMar 25, 2024
- CVE-2023-2874935Monitor
WordPress CM On Demand Search And Replace Plugin <= 1.3.0 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%cminds · cm search and replaceNov 22, 2023
- CVE-2025-4624635Monitor
WordPress CM Answers plugin <= 3.3.3 - Cross Site Request Forgery (CSRF) Vulnerability
HighCVSS 8.8No exploitEPSS 0%cminds · cm answersApr 22, 2025
- CVE-2025-4624535Monitor
WordPress CM Ad Changer plugin <= 2.0.5 - Cross Site Request Forgery (CSRF) Vulnerability
HighCVSS 8.8No exploitEPSS 0%cminds · cm ad changerApr 22, 2025
- CVE-2020-2414633Monitor
Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitr
HighCVSS 8.1No exploitEPSS 2%cminds · cm download managerJul 7, 2021
- CVE-2023-3075032Monitor
WordPress CM Pop-Up banners Plugin <= 1.5.10 is vulnerable to SQL Injection
HighCVSS 8.1No exploitEPSS 1%cminds · cm popupDec 20, 2023
- CVE-2024-516732Monitor
CM Email Registration Blacklist and Whitelist < 1.4.9 - Add/Delete Emails via CSRF Add and delete any item from blacklist/whitelist
HighCVSS 8.1No exploitEPSS 0%cminds · cm e-mail blacklistJul 13, 2024
- CVE-2022-307628Monitor
CM Download Manager < 2.8.6 - Admin+ Arbitrary File Upload
HighCVSS 7.2No exploitEPSS 2%cminds · cm download managerSep 26, 2022
- CVE-2014-912927Monitor
Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote at
MediumCVSS 6.8No exploitEPSS 2%cminds · cm download managerDec 5, 2014
- CVE-2024-123127Monitor
CM Download and File Manager < 2.9.0 - Download Unpublish via CSRF
MediumCVSS 6.8No exploitEPSS 0%cminds · cm download managerMar 25, 2024
- CVE-2024-502826Monitor
CM WordPress Search And Replace Plugin < 1.3.9 - Plugin Reset via CSRF
MediumCVSS 6.5No exploitEPSS 0%cminds · cm search and replaceJul 13, 2024
- CVE-2016-100013225Monitor
Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8
MediumCVSS 6.1Proof of conceptEPSS 4%cminds · tooltip glossaryOct 10, 2016
- CVE-2020-2734424Monitor
The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.
MediumCVSS 6.1No exploitEPSS 1%cminds · cm download managerOct 21, 2020
- CVE-2020-2414524Monitor
Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attac
MediumCVSS 6.1No exploitEPSS 1%cminds · cm download managerJul 7, 2021
- CVE-2021-2467821Monitor
CM Tooltip Glossary < 3.9.21 - Contributor+ Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%cminds · tooltip glossaryOct 4, 2021
- CVE-2021-2471319Monitor
Video Lessons Manager - Admin+ Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 1%cminds · video lessons managerNov 23, 2021
- CVE-2023-2599219Monitor
WordPress CM Answers Plugin <= 3.1.9 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%cminds · cm answersMar 23, 2023
- CVE-2023-3122819Monitor
WordPress CM On Demand Search And Replace Plugin <= 1.3.0 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%cminds · cm search and replaceAug 18, 2023
- CVE-2024-500419Monitor
CM Popup Plugin for WordPress < 1.6.6 - Contributor+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%cminds · cm popupJul 22, 2024
- CVE-2024-579919Monitor
CM Pop-Up Banners for WordPress < 1.7.3 - Contributor+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%cminds · cm popupSep 12, 2024
- CVE-2024-502619Monitor
CM Tooltip Glossary < 4.3.4 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%cminds · cm tooltip glossaryMay 15, 2025
- CVE-2024-123219Monitor
CM Download Manager < 2.9.0 - Download Deletion via CSRF
MediumCVSS 4.8No exploitEPSS 0%cminds · cm download managerMar 25, 2024
- CVE-2024-502919Monitor
CM Table Of Contents – WordPress TOC Plugin < 1.2.4 - Stored XSS via CSRF
MediumCVSS 4.8No exploitEPSS 0%cminds · cm table of contentsNov 21, 2024
- CVE-2024-503015Monitor
CM Table Of Contents – WordPress TOC Plugin < 1.2.3 - Settings Reset via CSRF
LowCVSS 3.8No exploitEPSS 0%cminds · cm table of contentsNov 18, 2024