Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2024-5799

Disclosure Date: September 12, 2024 (last updated September 27, 2024)
The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2024-5004

Disclosure Date: July 22, 2024 (last updated July 26, 2024)
The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2023-30750

Disclosure Date: December 20, 2023 (last updated December 27, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Popup Plugin for WordPress: from n/a through 1.5.10.
Attacker Value
Unknown

CVE-2023-28749

Disclosure Date: November 22, 2023 (last updated November 28, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.0 versions.
Attacker Value
Unknown

CVE-2023-31228

Disclosure Date: August 18, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.0 versions.
Attacker Value
Unknown

CVE-2023-25992

Disclosure Date: March 23, 2023 (last updated November 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeMindsSolutions CM Answers plugin <= 3.1.9 versions.
Attacker Value
Unknown

CVE-2022-3076

Disclosure Date: September 26, 2022 (last updated October 08, 2023)
The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.
Attacker Value
Unknown

CVE-2021-24678

Disclosure Date: October 04, 2021 (last updated November 28, 2024)
The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2020-24146

Disclosure Date: July 07, 2021 (last updated November 28, 2024)
Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.
Attacker Value
Unknown

CVE-2020-24145

Disclosure Date: July 07, 2021 (last updated November 28, 2024)
Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted deletescreenshot action.