Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cminds

First CVE: Dec 5, 2014Active for: 12 yearsTotal CVEs: 24
18.7
VTI Score
Low

Cminds develops a modestly sized suite of browser extensions and add-ons for productivity tasks such as download management, document search, table generation, and quick-answer retrieval. The vendor's vulnerability footprint is dominated by web-application-layer weakness classes including cross-site request forgery, cross-site scripting, path traversal, SQL injection, and unrestricted file upload, reflecting the attack surface inherent to browser-integrated tools that manipulate DOM, handle user input, and interact with backend services. These weakness classes are characteristic of web-facing software and recur across the vendor's product line, suggesting systemic input-validation and access-control challenges rather than isolated defects. Defenders who deploy these extensions should monitor this vendor's releases and assess whether affected versions are still active in their browser environments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cminds over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 5, 2014
11 years ago
Most Recent CVE
May 15, 2025
435 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-1000132MEDIUM
Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8
Oct 10, 20166.133NOYES
CVE-2025-46246HIGH
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Request Forgery.This issue affects CM Answers: from n/a through <=
Apr 22, 20258.824NONO
CVE-2025-46245HIGH
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site Request Forgery.This issue affects CM Ad Changer: from n/a t
Apr 22, 20258.824NONO
CVE-2023-28749HIGH
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.0 versions.
Nov 22, 20238.824NONO
CVE-2022-3076HIGH
The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, whi
Sep 26, 20227.224NONO
CVE-2024-5167HIGH
The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which coul
Jul 13, 20248.122NONO
CVE-2024-1962HIGH
The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF atta
Mar 25, 20248.822NONO
CVE-2023-30750HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Pop
Dec 20, 20238.122NONO
CVE-2020-24146HIGH
Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of
Jul 7, 20218.121NONO
CVE-2020-27344MEDIUM
The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.
Oct 21, 20206.121NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
63%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (4.2%)
Network22 (91.7%)
Unknown1 (4.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (95.8%)
High0 (0.0%)
Unknown1 (4.2%)
User Interaction
None4 (16.7%)
Unknown1 (4.2%)
Required19 (79.2%)
Privileges Required
Low5 (20.8%)
High10 (41.7%)
None8 (33.3%)
Unknown1 (4.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.2% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cminds.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cminds — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cminds's Products

View all 3 CNAs →

Top CWEs