Cminds develops a modestly sized suite of browser extensions and add-ons for productivity tasks such as download management, document search, table generation, and quick-answer retrieval. The vendor's vulnerability footprint is dominated by web-application-layer weakness classes including cross-site request forgery, cross-site scripting, path traversal, SQL injection, and unrestricted file upload, reflecting the attack surface inherent to browser-integrated tools that manipulate DOM, handle user input, and interact with backend services. These weakness classes are characteristic of web-facing software and recur across the vendor's product line, suggesting systemic input-validation and access-control challenges rather than isolated defects. Defenders who deploy these extensions should monitor this vendor's releases and assess whether affected versions are still active in their browser environments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cminds over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-1000132MEDIUM Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8 | Oct 10, 2016 | 6.1 | 33 | NO | YES |
CVE-2025-46246HIGH Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Request Forgery.This issue affects CM Answers: from n/a through <= | Apr 22, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-46245HIGH Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site Request Forgery.This issue affects CM Ad Changer: from n/a t | Apr 22, 2025 | 8.8 | 24 | NO | NO |
CVE-2023-28749HIGH Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.0 versions. | Nov 22, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-3076HIGH The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, whi | Sep 26, 2022 | 7.2 | 24 | NO | NO |
CVE-2024-5167HIGH The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which coul | Jul 13, 2024 | 8.1 | 22 | NO | NO |
CVE-2024-1962HIGH The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF atta | Mar 25, 2024 | 8.8 | 22 | NO | NO |
CVE-2023-30750HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Pop | Dec 20, 2023 | 8.1 | 22 | NO | NO |
CVE-2020-24146HIGH Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of | Jul 7, 2021 | 8.1 | 21 | NO | NO |
CVE-2020-27344MEDIUM The cm-download-manager plugin before 2.8.0 for WordPress allows XSS. | Oct 21, 2020 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cminds.
Media articles that mention a CVE ID that affects a product developed by Cminds — matched by CVE ID, not by vendor name.