codepeople kayıtları
codepeople üreticisine ait 64 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %48,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')31
- CWE-862 Missing Authorization10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-340 Generation of Predictable Numbers or Identifiers1
- CWE-400 Uncontrolled Resource Consumption1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
64 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2016-10916İstismar yok | The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.codepeople · appointment booking calendar · CWE-89 | Kritik9,8 | — | %1,8 | 22 Ağu 2019 |
40Planlayın | CVE-2016-10909İstismar yok | The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.codepeople · booking calendar contact form · CWE-89 | Kritik9,8 | — | %1,8 | 21 Ağu 2019 |
39İzleyin | CVE-2015-10099İstismar yok | CP Appointment Calendar Plugin dex_appointments.php dex_process_ready_to_go_appointment sql injectioncodepeople · cp appointment calendar · CWE-89 | Kritik9,8 | — | %1,0 | 10 Nis 2023 |
39İzleyin | CVE-2014-125091İstismar yok | codepeople cp-polls Plugin cp-admin-int-message-list.inc.php sql injectioncodepeople · polls cp · CWE-89 | Kritik9,8 | — | %0,8 | 4 Mar 2023 |
39İzleyin | CVE-2024-35735İstismar yok | WordPress WP Time Slots Booking Form plugin <= 1.2.11 - Broken Access Control vulnerabilitycodepeople · wp time slots booking form · CWE-862 | Kritik9,8 | — | %0,4 | 10 Haz 2024 |
39İzleyin | CVE-2025-46247İstismar yok | WordPress Appointment Booking Calendar plugin <= 1.3.92 - Broken Access Control Vulnerabilitycodepeople · appointment booking calendar · CWE-862 | Kritik9,8 | — | %0,4 | 22 Nis 2025 |
35İzleyin | CVE-2015-9233İstismar yok | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to codepeople · cp contact form with paypal · CWE-352 | Yüksek8,8 | — | %1,0 | 29 Eyl 2017 |
35İzleyin | CVE-2018-20964İstismar yok | The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.codepeople · contact form email · CWE-352 | Yüksek8,8 | — | %0,7 | 13 Ağu 2019 |
35İzleyin | CVE-2022-43482İstismar yok | WordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerabilitycodepeople · appointment booking calendar · CWE-862 | Yüksek8,8 | — | %0,5 | 18 Kas 2022 |
35İzleyin | CVE-2023-25039İstismar yok | WordPress Google Maps CP plugin <= 1.0.43 - Missing Authorization Leading To Feedback Submission Vulnerabilitycodepeople · google maps cp · CWE-862 | Yüksek8,8 | — | %0,5 | 25 Mar 2024 |
35İzleyin | CVE-2022-41790İstismar yok | WordPress WP Time Slots Booking Form Plugin <= 1.1.76 is vulnerable to Broken Access Controlcodepeople · wp time slots booking form · CWE-862 | Yüksek8,8 | — | %0,5 | 17 Oca 2024 |
35İzleyin | CVE-2024-0856İstismar yok | Booking Calendar < 1.3.83 - CSRF appointment schedulingcodepeople · appointment booking calendar · CWE-352 | Yüksek8,8 | — | %0,4 | 20 Mar 2024 |
35İzleyin | CVE-2023-27460İstismar yok | WordPress CP Contact Form with PayPal plugin <= 1.3.34 - Missing Authorization Leading To Feedback Submission vulnerabilitycodepeople · cp contact form with paypal · CWE-862 | Yüksek8,8 | — | %0,4 | 3 Haz 2024 |
35İzleyin | CVE-2025-46241İstismar yok | WordPress Appointment Booking Calendar plugin <= 1.3.92 - CSRF to SQL Injection vulnerabilitycodepeople · appointment booking calendar · CWE-352 | Yüksek8,8 | — | %0,2 | 22 Nis 2025 |
35İzleyin | CVE-2025-49291İstismar yok | WordPress Calculated Fields Form plugin <= 5.3.58 - Cross Site Request Forgery (CSRF) Vulnerabilitycodepeople · calculated fields form · CWE-352 | Yüksek8,8 | — | %0,2 | 6 Haz 2025 |
34İzleyin | CVE-2020-9372Kavram kanıtı | The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any bookingcodepeople · appointment booking calendar · CWE-1236 | Yüksek7,8 | — | %8,6 | 4 Mar 2020 |
31İzleyin | CVE-2015-7319İstismar yok | SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 focodepeople · appointment booking calendar · CWE-89 | Yüksek7,5 | — | %2,4 | 29 Eyl 2015 |
31İzleyin | CVE-2015-9348İstismar yok | The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.codepeople · sell downloads · CWE-20 | Yüksek7,5 | — | %1,7 | 27 Ağu 2019 |
30İzleyin | CVE-2024-12274İstismar yok | BookingPress < 1.1.23 - Unauthenticated Export File Downloadcodepeople · appointment booking calendar · CWE-340 | Yüksek7,5 | — | %0,6 | 13 Oca 2025 |
30İzleyin | CVE-2024-33543İstismar yok | WordPress WP Time Slots Booking Form plugin <= 1.2.06 - Broken Access Control vulnerabilitycodepeople · wp time slots booking form · CWE-862 | Yüksek7,5 | — | %0,4 | 9 Haz 2024 |
28İzleyin | CVE-2023-23895İstismar yok | WordPress WP Time Slots Booking Form plugin <= 1.1.82 - Broken Access Control vulnerabilitycodepeople · wp time slots booking form · CWE-862 | Yüksek7,2 | — | %0,7 | 9 Ara 2024 |
27İzleyin | CVE-2024-3632İstismar yok | Smart Image Gallery < 1.0.19 - Update/Delete Google API Key via CSRFcodepeople · smart image gallery · CWE-352 | Orta6,8 | — | %0,3 | 13 Tem 2024 |
26İzleyin | CVE-2024-36082İstismar yok | SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an admcodepeople · music store · CWE-89 | Orta6,5 | — | %0,5 | 7 Haz 2024 |
26İzleyin | CVE-2024-13680İstismar yok | Form Builder CP <= 1.2.41 - Authenticated (Contributor+) SQL Injectioncodepeople · form builder cp · CWE-89 | Orta6,5 | — | %0,5 | 24 Oca 2025 |
26İzleyin | CVE-2023-48318İstismar yok | WordPress Contact Form Email plugin <= 1.3.41 - Captcha Bypass vulnerabilitycodepeople · contact form email · CWE-307 | Orta6,5 | — | %0,3 | 4 Haz 2024 |
- CVE-2016-1091640Planlayın
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
KritikCVSS 9,8İstismar yokEPSS %2codepeople · appointment booking calendar22 Ağu 2019
- CVE-2016-1090940Planlayın
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
KritikCVSS 9,8İstismar yokEPSS %2codepeople · booking calendar contact form21 Ağu 2019
- CVE-2015-1009939İzleyin
CP Appointment Calendar Plugin dex_appointments.php dex_process_ready_to_go_appointment sql injection
KritikCVSS 9,8İstismar yokEPSS %1codepeople · cp appointment calendar10 Nis 2023
- CVE-2014-12509139İzleyin
codepeople cp-polls Plugin cp-admin-int-message-list.inc.php sql injection
KritikCVSS 9,8İstismar yokEPSS %1codepeople · polls cp4 Mar 2023
- CVE-2024-3573539İzleyin
WordPress WP Time Slots Booking Form plugin <= 1.2.11 - Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %0codepeople · wp time slots booking form10 Haz 2024
- CVE-2025-4624739İzleyin
WordPress Appointment Booking Calendar plugin <= 1.3.92 - Broken Access Control Vulnerability
KritikCVSS 9,8İstismar yokEPSS %0codepeople · appointment booking calendar22 Nis 2025
- CVE-2015-923335İzleyin
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to
YüksekCVSS 8,8İstismar yokEPSS %1codepeople · cp contact form with paypal29 Eyl 2017
- CVE-2018-2096435İzleyin
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
YüksekCVSS 8,8İstismar yokEPSS %1codepeople · contact form email13 Ağu 2019
- CVE-2022-4348235İzleyin
WordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1codepeople · appointment booking calendar18 Kas 2022
- CVE-2023-2503935İzleyin
WordPress Google Maps CP plugin <= 1.0.43 - Missing Authorization Leading To Feedback Submission Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0codepeople · google maps cp25 Mar 2024
- CVE-2022-4179035İzleyin
WordPress WP Time Slots Booking Form Plugin <= 1.1.76 is vulnerable to Broken Access Control
YüksekCVSS 8,8İstismar yokEPSS %0codepeople · wp time slots booking form17 Oca 2024
- CVE-2024-085635İzleyin
Booking Calendar < 1.3.83 - CSRF appointment scheduling
YüksekCVSS 8,8İstismar yokEPSS %0codepeople · appointment booking calendar20 Mar 2024
- CVE-2023-2746035İzleyin
WordPress CP Contact Form with PayPal plugin <= 1.3.34 - Missing Authorization Leading To Feedback Submission vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0codepeople · cp contact form with paypal3 Haz 2024
- CVE-2025-4624135İzleyin
WordPress Appointment Booking Calendar plugin <= 1.3.92 - CSRF to SQL Injection vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0codepeople · appointment booking calendar22 Nis 2025
- CVE-2025-4929135İzleyin
WordPress Calculated Fields Form plugin <= 5.3.58 - Cross Site Request Forgery (CSRF) Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0codepeople · calculated fields form6 Haz 2025
- CVE-2020-937234İzleyin
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking
YüksekCVSS 7,8Kavram kanıtıEPSS %9codepeople · appointment booking calendar4 Mar 2020
- CVE-2015-731931İzleyin
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 fo
YüksekCVSS 7,5İstismar yokEPSS %2codepeople · appointment booking calendar29 Eyl 2015
- CVE-2015-934831İzleyin
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
YüksekCVSS 7,5İstismar yokEPSS %2codepeople · sell downloads27 Ağu 2019
- CVE-2024-1227430İzleyin
BookingPress < 1.1.23 - Unauthenticated Export File Download
YüksekCVSS 7,5İstismar yokEPSS %1codepeople · appointment booking calendar13 Oca 2025
- CVE-2024-3354330İzleyin
WordPress WP Time Slots Booking Form plugin <= 1.2.06 - Broken Access Control vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0codepeople · wp time slots booking form9 Haz 2024
- CVE-2023-2389528İzleyin
WordPress WP Time Slots Booking Form plugin <= 1.1.82 - Broken Access Control vulnerability
YüksekCVSS 7,2İstismar yokEPSS %1codepeople · wp time slots booking form9 Ara 2024
- CVE-2024-363227İzleyin
Smart Image Gallery < 1.0.19 - Update/Delete Google API Key via CSRF
OrtaCVSS 6,8İstismar yokEPSS %0codepeople · smart image gallery13 Tem 2024
- CVE-2024-3608226İzleyin
SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an adm
OrtaCVSS 6,5İstismar yokEPSS %1codepeople · music store7 Haz 2024
- CVE-2024-1368026İzleyin
Form Builder CP <= 1.2.41 - Authenticated (Contributor+) SQL Injection
OrtaCVSS 6,5İstismar yokEPSS %0codepeople · form builder cp24 Oca 2025
- CVE-2023-4831826İzleyin
WordPress Contact Form Email plugin <= 1.3.41 - Captcha Bypass vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0codepeople · contact form email4 Haz 2024