Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cm Ad Changer HIGH 8.8
CVE-2025-46245

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site Request Forgery.This issue af…

Fix: 2.0.6+
Fix from $1,950 2025-04-22
Cm Answers HIGH 8.8
CVE-2025-46246

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Request Forgery.This issue affects …

Fix: 3.3.4+
Fix from $1,950 2025-04-22
Cm E Mail Blacklist HIGH 8.1
CVE-2024-5167

The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the bla…

Fix: 1.4.9+
Fix from $1,950 2024-07-13
Cm Search And Replace MEDIUM 6.5
CVE-2024-5028

The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to mak…

Fix: 1.3.9+
Fix from $1,600 2024-07-13
Cm Download Manager HIGH 8.8
CVE-2024-1962

The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins…

Fix: 2.9.1+
Fix from $1,950 2024-03-25
Cm Download Manager MEDIUM 6.8
CVE-2024-1231

The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins…

Fix: 2.9.0+
Fix from $1,600 2024-03-25
Cm Popup HIGH 8.1
CVE-2023-30750

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for Word…

Fix: 1.6.0+
Fix from $1,950 2023-12-20
Cm Search And Replace HIGH 8.8
CVE-2023-28749

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.0 versions.

Fix: after 1.3.0
Fix from $1,950 2023-11-22
Cm Download Manager HIGH 7.2
CVE-2022-3076

The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extensio…

Fix: 2.8.6+
Fix from $1,950 2022-09-26
Tooltip Glossary MEDIUM 5.4
CVE-2021-24678

The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as …

Fix: 3.9.21+
Fix from $1,600 2021-10-04
Cm Download Manager HIGH 8.1
CVE-2020-24146

Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files…

Mitigation only
Fix from $1,950 2021-07-07
Cm Download Manager MEDIUM 6.1
CVE-2020-24145

Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to i…

Mitigation only
Fix from $1,600 2021-07-07
Cm Download Manager MEDIUM 6.1
CVE-2020-27344

The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.

Fix: 2.8.0+
Fix from $1,600 2020-10-21
Tooltip Glossary MEDIUM 6.1
CVE-2016-1000132

Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8

Fix: after 3.2.8
Fix from $1,600 2016-10-10
Cm Download Manager MEDIUM 6.8
CVE-2014-9129

Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers t…

Fix: after 2.0.6
Fix from $1,600 2014-12-05