cminds CVE Vulnerabilities & Metrics

Focus on cminds vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About cminds Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with cminds. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total cminds CVEs: 11
Earliest CVE date: 05 Dec 2014, 15:59 UTC
Latest CVE date: 12 Sep 2024, 06:15 UTC

Latest CVE reference: CVE-2024-5799

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -33.33%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -33.33%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical cminds CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.39

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 7
4.0-6.9 5
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS cminds CVEs

These are the five CVEs with the highest CVSS scores for cminds, sorted by severity first and recency.

All CVEs for cminds

CVE-2024-5799 cminds vulnerability CVSS: 0 12 Sep 2024, 06:15 UTC

The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.

CVE-2024-5004 cminds vulnerability CVSS: 0 22 Jul 2024, 06:15 UTC

The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2023-30750 cminds vulnerability CVSS: 0 20 Dec 2023, 17:15 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Popup Plugin for WordPress: from n/a through 1.5.10.

CVE-2023-28749 cminds vulnerability CVSS: 0 22 Nov 2023, 13:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.0 versions.

CVE-2023-31228 cminds vulnerability CVSS: 0 18 Aug 2023, 13:15 UTC

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.0 versions.

CVE-2022-3076 cminds vulnerability CVSS: 0 26 Sep 2022, 13:15 UTC

The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.

CVE-2021-24678 cminds vulnerability CVSS: 3.5 04 Oct 2021, 12:15 UTC

The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks

CVE-2020-24146 cminds vulnerability CVSS: 5.5 07 Jul 2021, 14:15 UTC

Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.

CVE-2020-24145 cminds vulnerability CVSS: 4.3 07 Jul 2021, 14:15 UTC

Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted deletescreenshot action.

CVE-2020-27344 cminds vulnerability CVSS: 4.3 21 Oct 2020, 20:15 UTC

The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.

CVE-2016-1000132 cminds vulnerability CVSS: 4.3 10 Oct 2016, 20:59 UTC

Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8

CVE-2014-9129 cminds vulnerability CVSS: 6.8 05 Dec 2014, 15:59 UTC

Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page to wp-admin/admin.php.