Skip to content
Noroxi

codepeople records

64 published records for vendor codepeople.

All records

64 records
  • The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.

    CriticalCVSS 9.8No exploitEPSS 2%

    codepeople · appointment booking calendarAug 22, 2019

  • The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.

    CriticalCVSS 9.8No exploitEPSS 2%

    codepeople · booking calendar contact formAug 21, 2019

  • CP Appointment Calendar Plugin dex_appointments.php dex_process_ready_to_go_appointment sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    codepeople · cp appointment calendarApr 10, 2023

  • codepeople cp-polls Plugin cp-admin-int-message-list.inc.php sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    codepeople · polls cpMar 4, 2023

  • WordPress WP Time Slots Booking Form plugin <= 1.2.11 - Broken Access Control vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    codepeople · wp time slots booking formJun 10, 2024

  • WordPress Appointment Booking Calendar plugin <= 1.3.92 - Broken Access Control Vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    codepeople · appointment booking calendarApr 22, 2025

  • CVE-2015-9233
    35Monitor

    The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to

    HighCVSS 8.8No exploitEPSS 1%

    codepeople · cp contact form with paypalSep 29, 2017

  • The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.

    HighCVSS 8.8No exploitEPSS 1%

    codepeople · contact form emailAug 13, 2019

  • WordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    codepeople · appointment booking calendarNov 18, 2022

  • WordPress Google Maps CP plugin <= 1.0.43 - Missing Authorization Leading To Feedback Submission Vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    codepeople · google maps cpMar 25, 2024

  • WordPress WP Time Slots Booking Form Plugin <= 1.1.76 is vulnerable to Broken Access Control

    HighCVSS 8.8No exploitEPSS 0%

    codepeople · wp time slots booking formJan 17, 2024

  • CVE-2024-0856
    35Monitor

    Booking Calendar < 1.3.83 - CSRF appointment scheduling

    HighCVSS 8.8No exploitEPSS 0%

    codepeople · appointment booking calendarMar 20, 2024

  • WordPress CP Contact Form with PayPal plugin <= 1.3.34 - Missing Authorization Leading To Feedback Submission vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    codepeople · cp contact form with paypalJun 3, 2024

  • WordPress Appointment Booking Calendar plugin <= 1.3.92 - CSRF to SQL Injection vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    codepeople · appointment booking calendarApr 22, 2025

  • WordPress Calculated Fields Form plugin <= 5.3.58 - Cross Site Request Forgery (CSRF) Vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    codepeople · calculated fields formJun 6, 2025

  • CVE-2020-9372
    34Monitor

    The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking

    HighCVSS 7.8Proof of conceptEPSS 9%

    codepeople · appointment booking calendarMar 4, 2020

  • CVE-2015-7319
    31Monitor

    SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 fo

    HighCVSS 7.5No exploitEPSS 2%

    codepeople · appointment booking calendarSep 29, 2015

  • CVE-2015-9348
    31Monitor

    The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.

    HighCVSS 7.5No exploitEPSS 2%

    codepeople · sell downloadsAug 27, 2019

  • BookingPress < 1.1.23 - Unauthenticated Export File Download

    HighCVSS 7.5No exploitEPSS 1%

    codepeople · appointment booking calendarJan 13, 2025

  • WordPress WP Time Slots Booking Form plugin <= 1.2.06 - Broken Access Control vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    codepeople · wp time slots booking formJun 9, 2024

  • WordPress WP Time Slots Booking Form plugin <= 1.1.82 - Broken Access Control vulnerability

    HighCVSS 7.2No exploitEPSS 1%

    codepeople · wp time slots booking formDec 9, 2024

  • CVE-2024-3632
    27Monitor

    Smart Image Gallery < 1.0.19 - Update/Delete Google API Key via CSRF

    MediumCVSS 6.8No exploitEPSS 0%

    codepeople · smart image galleryJul 13, 2024

  • SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an adm

    MediumCVSS 6.5No exploitEPSS 1%

    codepeople · music storeJun 7, 2024

  • Form Builder CP <= 1.2.41 - Authenticated (Contributor+) SQL Injection

    MediumCVSS 6.5No exploitEPSS 0%

    codepeople · form builder cpJan 24, 2025

  • WordPress Contact Form Email plugin <= 1.3.41 - Captcha Bypass vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    codepeople · contact form emailJun 4, 2024