VendorsCmindscm_download_managerany version
Vulnerabilities

Cminds CreativeMinds CM Download Manager 2.7.0 for WordPress any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2024-1962
CM Download and File Manager < 2.9.1 - Download Edit via CSRF
Published 2024-03-25 · Analyzed
8.8EPSS 0.005
CVE-2022-3076
CM Download Manager < 2.8.6 - Admin+ Arbitrary File Upload
Published 2022-09-26 · Modified
7.2EPSS 0.015
CVE-2014-9129
Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page to wp-admin/admin.php.
Published 2014-12-05 · Modified
6.8EPSS 0.015
CVE-2024-1231
CM Download and File Manager < 2.9.0 - Download Unpublish via CSRF
Published 2024-03-25 · Analyzed
6.8EPSS 0.002
CVE-2020-27344
The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.
Published 2020-10-21 · Modified
6.1EPSS 0.010
CVE-2024-1232
CM Download Manager < 2.9.0 - Download Deletion via CSRF
Published 2024-03-25 · Analyzed
4.8EPSS 0.002