İçeriğe atla
Noroxi

codepeople kayıtları

codepeople üreticisine ait 64 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%48,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

64 kayıt
  • CVE-2016-10916
    40Planlayın

    The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.

    KritikCVSS 9,8İstismar yokEPSS %2

    codepeople · appointment booking calendar22 Ağu 2019

  • CVE-2016-10909
    40Planlayın

    The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.

    KritikCVSS 9,8İstismar yokEPSS %2

    codepeople · booking calendar contact form21 Ağu 2019

  • CVE-2015-10099
    39İzleyin

    CP Appointment Calendar Plugin dex_appointments.php dex_process_ready_to_go_appointment sql injection

    KritikCVSS 9,8İstismar yokEPSS %1

    codepeople · cp appointment calendar10 Nis 2023

  • CVE-2014-125091
    39İzleyin

    codepeople cp-polls Plugin cp-admin-int-message-list.inc.php sql injection

    KritikCVSS 9,8İstismar yokEPSS %1

    codepeople · polls cp4 Mar 2023

  • CVE-2024-35735
    39İzleyin

    WordPress WP Time Slots Booking Form plugin <= 1.2.11 - Broken Access Control vulnerability

    KritikCVSS 9,8İstismar yokEPSS %0

    codepeople · wp time slots booking form10 Haz 2024

  • CVE-2025-46247
    39İzleyin

    WordPress Appointment Booking Calendar plugin <= 1.3.92 - Broken Access Control Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %0

    codepeople · appointment booking calendar22 Nis 2025

  • CVE-2015-9233
    35İzleyin

    The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to

    YüksekCVSS 8,8İstismar yokEPSS %1

    codepeople · cp contact form with paypal29 Eyl 2017

  • CVE-2018-20964
    35İzleyin

    The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.

    YüksekCVSS 8,8İstismar yokEPSS %1

    codepeople · contact form email13 Ağu 2019

  • CVE-2022-43482
    35İzleyin

    WordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    codepeople · appointment booking calendar18 Kas 2022

  • CVE-2023-25039
    35İzleyin

    WordPress Google Maps CP plugin <= 1.0.43 - Missing Authorization Leading To Feedback Submission Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    codepeople · google maps cp25 Mar 2024

  • CVE-2022-41790
    35İzleyin

    WordPress WP Time Slots Booking Form Plugin <= 1.1.76 is vulnerable to Broken Access Control

    YüksekCVSS 8,8İstismar yokEPSS %0

    codepeople · wp time slots booking form17 Oca 2024

  • CVE-2024-0856
    35İzleyin

    Booking Calendar < 1.3.83 - CSRF appointment scheduling

    YüksekCVSS 8,8İstismar yokEPSS %0

    codepeople · appointment booking calendar20 Mar 2024

  • CVE-2023-27460
    35İzleyin

    WordPress CP Contact Form with PayPal plugin <= 1.3.34 - Missing Authorization Leading To Feedback Submission vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    codepeople · cp contact form with paypal3 Haz 2024

  • CVE-2025-46241
    35İzleyin

    WordPress Appointment Booking Calendar plugin <= 1.3.92 - CSRF to SQL Injection vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    codepeople · appointment booking calendar22 Nis 2025

  • CVE-2025-49291
    35İzleyin

    WordPress Calculated Fields Form plugin <= 5.3.58 - Cross Site Request Forgery (CSRF) Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    codepeople · calculated fields form6 Haz 2025

  • CVE-2020-9372
    34İzleyin

    The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking

    YüksekCVSS 7,8Kavram kanıtıEPSS %9

    codepeople · appointment booking calendar4 Mar 2020

  • CVE-2015-7319
    31İzleyin

    SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 fo

    YüksekCVSS 7,5İstismar yokEPSS %2

    codepeople · appointment booking calendar29 Eyl 2015

  • CVE-2015-9348
    31İzleyin

    The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.

    YüksekCVSS 7,5İstismar yokEPSS %2

    codepeople · sell downloads27 Ağu 2019

  • CVE-2024-12274
    30İzleyin

    BookingPress < 1.1.23 - Unauthenticated Export File Download

    YüksekCVSS 7,5İstismar yokEPSS %1

    codepeople · appointment booking calendar13 Oca 2025

  • CVE-2024-33543
    30İzleyin

    WordPress WP Time Slots Booking Form plugin <= 1.2.06 - Broken Access Control vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %0

    codepeople · wp time slots booking form9 Haz 2024

  • CVE-2023-23895
    28İzleyin

    WordPress WP Time Slots Booking Form plugin <= 1.1.82 - Broken Access Control vulnerability

    YüksekCVSS 7,2İstismar yokEPSS %1

    codepeople · wp time slots booking form9 Ara 2024

  • CVE-2024-3632
    27İzleyin

    Smart Image Gallery < 1.0.19 - Update/Delete Google API Key via CSRF

    OrtaCVSS 6,8İstismar yokEPSS %0

    codepeople · smart image gallery13 Tem 2024

  • CVE-2024-36082
    26İzleyin

    SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an adm

    OrtaCVSS 6,5İstismar yokEPSS %1

    codepeople · music store7 Haz 2024

  • CVE-2024-13680
    26İzleyin

    Form Builder CP <= 1.2.41 - Authenticated (Contributor+) SQL Injection

    OrtaCVSS 6,5İstismar yokEPSS %0

    codepeople · form builder cp24 Oca 2025

  • CVE-2023-48318
    26İzleyin

    WordPress Contact Form Email plugin <= 1.3.41 - Captcha Bypass vulnerability

    OrtaCVSS 6,5İstismar yokEPSS %0

    codepeople · contact form email4 Haz 2024