Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2024-5799
Disclosure Date: September 12, 2024 (last updated September 27, 2024)
The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2024-5004
Disclosure Date: July 22, 2024 (last updated July 26, 2024)
The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2023-30750
Disclosure Date: December 20, 2023 (last updated December 27, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Popup Plugin for WordPress: from n/a through 1.5.10.
0
Attacker Value
Unknown
CVE-2023-28749
Disclosure Date: November 22, 2023 (last updated November 28, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.0 versions.
0
Attacker Value
Unknown
CVE-2023-31228
Disclosure Date: August 18, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.0 versions.
0
Attacker Value
Unknown
CVE-2023-25992
Disclosure Date: March 23, 2023 (last updated November 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeMindsSolutions CM Answers plugin <= 3.1.9 versions.
0
Attacker Value
Unknown
CVE-2022-3076
Disclosure Date: September 26, 2022 (last updated October 08, 2023)
The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.
0
Attacker Value
Unknown
CVE-2021-24678
Disclosure Date: October 04, 2021 (last updated November 28, 2024)
The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2020-24146
Disclosure Date: July 07, 2021 (last updated November 28, 2024)
Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.
0
Attacker Value
Unknown
CVE-2020-24145
Disclosure Date: July 07, 2021 (last updated November 28, 2024)
Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted deletescreenshot action.
0