Vulnerabilities and security researches forcm-video-lesson-manager cm-video-lesson-manager
Direction: ascendingJun 06, 2024
Video Lessons Manager – WordPress LMS Plugin # CVE-2021-24713
- CVE, Research URL
- Date
- Nov 24, 2021
- Research Description
- The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Nov 27, 2024
Video Lessons Manager – WordPress LMS Plugin # CVE-2024-11202
- CVE, Research URL
- Date
- Nov 26, 2024
- Research Description
- Video Lessons Manager – WordPress LMS Plugin [cm-video-lesson-manager] < 1.8.3 CVE-2024-11202 [en] Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Feb 16, 2025
Video Lessons Manager – WordPress LMS Plugin # CVE-2025-24758
- CVE, Research URL
- Date
- Mar 03, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows Reflected XSS. This issue affects CM Map Locations: from n/a through 2.0.8.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable