cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcm-download-manager cm-download-manager

Direction: ascending
Jun 06, 2024

CM Download Manager – Document and File Management # CVE-2020-27344

CVE, Research URL

CVE-2020-27344

Date
Oct 22, 2020
Research Description
The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.
Affected versions
Min -, max -.
Status
vulnerable

CM Download Manager – Document and File Management # CVE-2014-8877

CVE, Research URL

CVE-2014-8877

Date
Dec 05, 2014
Research Description
The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function.
Affected versions
Min -, max -.
Status
vulnerable

CM Download Manager – Document and File Management # CVE-2024-1962

CVE, Research URL

CVE-2024-1962

Date
Mar 25, 2024
Research Description
The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF attack
Affected versions
Min -, max -.
Status
vulnerable

CM Download Manager – Document and File Management # CVE-2014-9129

CVE, Research URL

CVE-2014-9129

Date
Dec 05, 2014
Research Description
Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page to wp-admin/admin.php.
Affected versions
Min -, max -.
Status
vulnerable

CM Download Manager – Document and File Management # CVE-2022-3076

CVE, Research URL

CVE-2022-3076

Date
Sep 26, 2022
Research Description
The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.
Affected versions
Min -, max -.
Status
vulnerable

CM Download Manager – Document and File Management # CVE-2024-1231

CVE, Research URL

CVE-2024-1231

Date
Mar 25, 2024
Research Description
The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack
Affected versions
Min -, max -.
Status
vulnerable

CM Download Manager – Document and File Management # CVE-2020-24145

CVE, Research URL

CVE-2020-24145

Date
Jul 07, 2021
Research Description
Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted deletescreenshot action.
Affected versions
Min -, max -.
Status
vulnerable

CM Download Manager – Document and File Management # CVE-2020-24146

CVE, Research URL

CVE-2020-24146

Date
Jul 07, 2021
Research Description
Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.
Affected versions
Min -, max -.
Status
vulnerable

CM Download Manager – Document and File Management # CVE-2024-1232

CVE, Research URL

CVE-2024-1232

Date
Mar 25, 2024
Research Description
The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete downloads via a CSRF attack
Affected versions
Min -, max -.
Status
vulnerable
Feb 19, 2025

CM Download Manager – Document and File Management # CVE-2025-24758

CVE, Research URL

CVE-2025-24758

Date
Mar 03, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows Reflected XSS. This issue affects CM Map Locations: from n/a through 2.0.8.
Affected versions
Min -, max -.
Status
vulnerable
Apr 03, 2025

CM Download Manager – Document and File Management # CVE-2025-30910

CVE, Research URL

CVE-2025-30910

Date
Apr 01, 2025
Research Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CreativeMindsSolutions CM Download Manager allows Path Traversal. This issue affects CM Download Manager: from n/a through 2.9.6.
Affected versions
Min -, max -.
Status
vulnerable