Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Cminds

24 known vulnerabilities

5
HIGH
17
MEDIUM
1
LOW

Top Products

cm download manager 7 cm popup 3 cm search and replace 3 cm answers 2 cm table of contents 2 tooltip glossary 2 cm tooltip glossary 1 cm ad changer 1 cm e-mail blacklist 1 video lessons manager 1
23 CVEs
4.8
CVE-2024-5026

The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could all

4.3
CVE-2025-46246

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Reques

4.3
CVE-2025-46245

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site

4.8
CVE-2024-5029

The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is miss

3.8
CVE-2024-5030

The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, w

4.8
CVE-2024-5799

The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which cou

4.8
CVE-2024-5004

The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign setti

8.1
CVE-2024-5167

The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or

6.5
CVE-2024-5028

The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which

8.8
CVE-2024-1962

The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attac

4.8
CVE-2024-1232

The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attac

6.8
CVE-2024-1231

The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attac

8.5
CVE-2023-30750

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolut

4.3
CVE-2023-28749

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.

5.9
CVE-2023-31228

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace

5.9
CVE-2023-25992

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeMindsSolutions CM Answers plugin <= 3.1.9 vers

7.2
CVE-2022-3076

The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary file

4.8
CVE-2021-24713

The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do n

5.4
CVE-2021-24678

The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which

8.1
CVE-2020-24146

Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized us

6.1
CVE-2020-24145

Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress

6.1
CVE-2020-27344

The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.

6.1
CVE-2016-1000132

Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8

Frequently Asked Questions

How many CVEs affect Cminds?

Cminds has 24 CVE records in our database, including 0 critical and 5 high severity vulnerabilities.

What are the most severe Cminds vulnerabilities?

Cminds has 0 critical severity (CVSS 9.0+) and 5 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Cminds vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Cminds products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Cminds Vulnerabilities

CyberStrike scans your infrastructure for Cminds vulnerabilities and provides real-time remediation guidance.

Get Started