codepeople records
64 published records for vendor codepeople.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 48.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')31
- CWE-862 Missing Authorization10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-340 Generation of Predictable Numbers or Identifiers1
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAll records
64 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-10916No exploit | The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.codepeople · appointment booking calendar · CWE-89 | Critical9.8 | — | 1.8% | Aug 22, 2019 |
40Plan | CVE-2016-10909No exploit | The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.codepeople · booking calendar contact form · CWE-89 | Critical9.8 | — | 1.8% | Aug 21, 2019 |
39Monitor | CVE-2015-10099No exploit | CP Appointment Calendar Plugin dex_appointments.php dex_process_ready_to_go_appointment sql injectioncodepeople · cp appointment calendar · CWE-89 | Critical9.8 | — | 1.0% | Apr 10, 2023 |
39Monitor | CVE-2014-125091No exploit | codepeople cp-polls Plugin cp-admin-int-message-list.inc.php sql injectioncodepeople · polls cp · CWE-89 | Critical9.8 | — | 0.8% | Mar 4, 2023 |
39Monitor | CVE-2024-35735No exploit | WordPress WP Time Slots Booking Form plugin <= 1.2.11 - Broken Access Control vulnerabilitycodepeople · wp time slots booking form · CWE-862 | Critical9.8 | — | 0.4% | Jun 10, 2024 |
39Monitor | CVE-2025-46247No exploit | WordPress Appointment Booking Calendar plugin <= 1.3.92 - Broken Access Control Vulnerabilitycodepeople · appointment booking calendar · CWE-862 | Critical9.8 | — | 0.4% | Apr 22, 2025 |
35Monitor | CVE-2015-9233No exploit | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to codepeople · cp contact form with paypal · CWE-352 | High8.8 | — | 1.0% | Sep 29, 2017 |
35Monitor | CVE-2018-20964No exploit | The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.codepeople · contact form email · CWE-352 | High8.8 | — | 0.7% | Aug 13, 2019 |
35Monitor | CVE-2022-43482No exploit | WordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerabilitycodepeople · appointment booking calendar · CWE-862 | High8.8 | — | 0.5% | Nov 18, 2022 |
35Monitor | CVE-2023-25039No exploit | WordPress Google Maps CP plugin <= 1.0.43 - Missing Authorization Leading To Feedback Submission Vulnerabilitycodepeople · google maps cp · CWE-862 | High8.8 | — | 0.5% | Mar 25, 2024 |
35Monitor | CVE-2022-41790No exploit | WordPress WP Time Slots Booking Form Plugin <= 1.1.76 is vulnerable to Broken Access Controlcodepeople · wp time slots booking form · CWE-862 | High8.8 | — | 0.5% | Jan 17, 2024 |
35Monitor | CVE-2024-0856No exploit | Booking Calendar < 1.3.83 - CSRF appointment schedulingcodepeople · appointment booking calendar · CWE-352 | High8.8 | — | 0.4% | Mar 20, 2024 |
35Monitor | CVE-2023-27460No exploit | WordPress CP Contact Form with PayPal plugin <= 1.3.34 - Missing Authorization Leading To Feedback Submission vulnerabilitycodepeople · cp contact form with paypal · CWE-862 | High8.8 | — | 0.4% | Jun 3, 2024 |
35Monitor | CVE-2025-46241No exploit | WordPress Appointment Booking Calendar plugin <= 1.3.92 - CSRF to SQL Injection vulnerabilitycodepeople · appointment booking calendar · CWE-352 | High8.8 | — | 0.2% | Apr 22, 2025 |
35Monitor | CVE-2025-49291No exploit | WordPress Calculated Fields Form plugin <= 5.3.58 - Cross Site Request Forgery (CSRF) Vulnerabilitycodepeople · calculated fields form · CWE-352 | High8.8 | — | 0.2% | Jun 6, 2025 |
34Monitor | CVE-2020-9372Proof of concept | The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any bookingcodepeople · appointment booking calendar · CWE-1236 | High7.8 | — | 8.6% | Mar 4, 2020 |
31Monitor | CVE-2015-7319No exploit | SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 focodepeople · appointment booking calendar · CWE-89 | High7.5 | — | 2.4% | Sep 29, 2015 |
31Monitor | CVE-2015-9348No exploit | The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.codepeople · sell downloads · CWE-20 | High7.5 | — | 1.7% | Aug 27, 2019 |
30Monitor | CVE-2024-12274No exploit | BookingPress < 1.1.23 - Unauthenticated Export File Downloadcodepeople · appointment booking calendar · CWE-340 | High7.5 | — | 0.6% | Jan 13, 2025 |
30Monitor | CVE-2024-33543No exploit | WordPress WP Time Slots Booking Form plugin <= 1.2.06 - Broken Access Control vulnerabilitycodepeople · wp time slots booking form · CWE-862 | High7.5 | — | 0.4% | Jun 9, 2024 |
28Monitor | CVE-2023-23895No exploit | WordPress WP Time Slots Booking Form plugin <= 1.1.82 - Broken Access Control vulnerabilitycodepeople · wp time slots booking form · CWE-862 | High7.2 | — | 0.7% | Dec 9, 2024 |
27Monitor | CVE-2024-3632No exploit | Smart Image Gallery < 1.0.19 - Update/Delete Google API Key via CSRFcodepeople · smart image gallery · CWE-352 | Medium6.8 | — | 0.3% | Jul 13, 2024 |
26Monitor | CVE-2024-36082No exploit | SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an admcodepeople · music store · CWE-89 | Medium6.5 | — | 0.5% | Jun 7, 2024 |
26Monitor | CVE-2024-13680No exploit | Form Builder CP <= 1.2.41 - Authenticated (Contributor+) SQL Injectioncodepeople · form builder cp · CWE-89 | Medium6.5 | — | 0.5% | Jan 24, 2025 |
26Monitor | CVE-2023-48318No exploit | WordPress Contact Form Email plugin <= 1.3.41 - Captcha Bypass vulnerabilitycodepeople · contact form email · CWE-307 | Medium6.5 | — | 0.3% | Jun 4, 2024 |
- CVE-2016-1091640Plan
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
CriticalCVSS 9.8No exploitEPSS 2%codepeople · appointment booking calendarAug 22, 2019
- CVE-2016-1090940Plan
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
CriticalCVSS 9.8No exploitEPSS 2%codepeople · booking calendar contact formAug 21, 2019
- CVE-2015-1009939Monitor
CP Appointment Calendar Plugin dex_appointments.php dex_process_ready_to_go_appointment sql injection
CriticalCVSS 9.8No exploitEPSS 1%codepeople · cp appointment calendarApr 10, 2023
- CVE-2014-12509139Monitor
codepeople cp-polls Plugin cp-admin-int-message-list.inc.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%codepeople · polls cpMar 4, 2023
- CVE-2024-3573539Monitor
WordPress WP Time Slots Booking Form plugin <= 1.2.11 - Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 0%codepeople · wp time slots booking formJun 10, 2024
- CVE-2025-4624739Monitor
WordPress Appointment Booking Calendar plugin <= 1.3.92 - Broken Access Control Vulnerability
CriticalCVSS 9.8No exploitEPSS 0%codepeople · appointment booking calendarApr 22, 2025
- CVE-2015-923335Monitor
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to
HighCVSS 8.8No exploitEPSS 1%codepeople · cp contact form with paypalSep 29, 2017
- CVE-2018-2096435Monitor
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
HighCVSS 8.8No exploitEPSS 1%codepeople · contact form emailAug 13, 2019
- CVE-2022-4348235Monitor
WordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerability
HighCVSS 8.8No exploitEPSS 1%codepeople · appointment booking calendarNov 18, 2022
- CVE-2023-2503935Monitor
WordPress Google Maps CP plugin <= 1.0.43 - Missing Authorization Leading To Feedback Submission Vulnerability
HighCVSS 8.8No exploitEPSS 0%codepeople · google maps cpMar 25, 2024
- CVE-2022-4179035Monitor
WordPress WP Time Slots Booking Form Plugin <= 1.1.76 is vulnerable to Broken Access Control
HighCVSS 8.8No exploitEPSS 0%codepeople · wp time slots booking formJan 17, 2024
- CVE-2024-085635Monitor
Booking Calendar < 1.3.83 - CSRF appointment scheduling
HighCVSS 8.8No exploitEPSS 0%codepeople · appointment booking calendarMar 20, 2024
- CVE-2023-2746035Monitor
WordPress CP Contact Form with PayPal plugin <= 1.3.34 - Missing Authorization Leading To Feedback Submission vulnerability
HighCVSS 8.8No exploitEPSS 0%codepeople · cp contact form with paypalJun 3, 2024
- CVE-2025-4624135Monitor
WordPress Appointment Booking Calendar plugin <= 1.3.92 - CSRF to SQL Injection vulnerability
HighCVSS 8.8No exploitEPSS 0%codepeople · appointment booking calendarApr 22, 2025
- CVE-2025-4929135Monitor
WordPress Calculated Fields Form plugin <= 5.3.58 - Cross Site Request Forgery (CSRF) Vulnerability
HighCVSS 8.8No exploitEPSS 0%codepeople · calculated fields formJun 6, 2025
- CVE-2020-937234Monitor
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking
HighCVSS 7.8Proof of conceptEPSS 9%codepeople · appointment booking calendarMar 4, 2020
- CVE-2015-731931Monitor
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 fo
HighCVSS 7.5No exploitEPSS 2%codepeople · appointment booking calendarSep 29, 2015
- CVE-2015-934831Monitor
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
HighCVSS 7.5No exploitEPSS 2%codepeople · sell downloadsAug 27, 2019
- CVE-2024-1227430Monitor
BookingPress < 1.1.23 - Unauthenticated Export File Download
HighCVSS 7.5No exploitEPSS 1%codepeople · appointment booking calendarJan 13, 2025
- CVE-2024-3354330Monitor
WordPress WP Time Slots Booking Form plugin <= 1.2.06 - Broken Access Control vulnerability
HighCVSS 7.5No exploitEPSS 0%codepeople · wp time slots booking formJun 9, 2024
- CVE-2023-2389528Monitor
WordPress WP Time Slots Booking Form plugin <= 1.1.82 - Broken Access Control vulnerability
HighCVSS 7.2No exploitEPSS 1%codepeople · wp time slots booking formDec 9, 2024
- CVE-2024-363227Monitor
Smart Image Gallery < 1.0.19 - Update/Delete Google API Key via CSRF
MediumCVSS 6.8No exploitEPSS 0%codepeople · smart image galleryJul 13, 2024
- CVE-2024-3608226Monitor
SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an adm
MediumCVSS 6.5No exploitEPSS 1%codepeople · music storeJun 7, 2024
- CVE-2024-1368026Monitor
Form Builder CP <= 1.2.41 - Authenticated (Contributor+) SQL Injection
MediumCVSS 6.5No exploitEPSS 0%codepeople · form builder cpJan 24, 2025
- CVE-2023-4831826Monitor
WordPress Contact Form Email plugin <= 1.3.41 - Captcha Bypass vulnerability
MediumCVSS 6.5No exploitEPSS 0%codepeople · contact form emailJun 4, 2024