Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
codepeople vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-5953
Multiple cross-site scripting (XSS) vulnerabilities in tmpl/layout_editevent.php in the Multi Calendar (com_multicalendar) component 4.0.2, and possibly 4.8.5 and previous versions, for Joomla! allow remote malicious users to inject arbitrary web script or HTML via the (1) calid ...
Codepeople Com Multicalendar 4.0.2
Codepeople Com Multicalendar
6.1
CVSSv3
CVE-2014-10395
The cp-polls plugin prior to 1.0.1 for WordPress has XSS in the votes list.
Codepeople Polls Cp
6.1
CVSSv3
CVE-2016-10992
The music-store plugin prior to 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from_year parameter.
Codepeople Music Store
6.1
CVSSv3
CVE-2015-9346
The cp-polls plugin prior to 1.0.5 for WordPress has XSS.
Codepeople Polls Cp
7.5
CVSSv3
CVE-2015-9348
The sell-downloads plugin prior to 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
Codepeople Sell Downloads
5.3
CVSSv3
CVE-2024-31302
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from n/a up to and including 1.3.44.
Codepeople Contact Form Email
9.8
CVSSv3
CVE-2014-125091
A vulnerability has been found in codepeople cp-polls Plugin 1.0.1 on WordPress and classified as critical. This vulnerability affects unknown code of the file cp-admin-int-message-list.inc.php. The manipulation of the argument lu leads to sql injection. The attack can be initiat...
Codepeople Polls Cp 1.0.1
4.8
CVSSv3
CVE-2022-2567
The Form Builder CP WordPress plugin prior to 1.2.32 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in ...
Codepeople Form Builder Cp
1 Github repository
6.1
CVSSv3
CVE-2018-20963
The contact-form-to-email plugin prior to 1.2.66 for WordPress has XSS.
Codepeople Contact Form Email
8.8
CVSSv3
CVE-2018-20964
The contact-form-to-email plugin prior to 1.2.66 for WordPress has CSRF.
Codepeople Contact Form Email
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »