Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Calculated Fields Form HIGH 8.8
CVE-2025-49291

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Cross Site Request Forgery.This is…

Fix: 5.3.59+
Fix from $1,950 2025-06-06
Polls Cp MEDIUM 5.4
CVE-2024-8854

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as ad…

Fix: 1.0.77+
Fix from $1,600 2025-05-15
Polls Cp MEDIUM 5.4
CVE-2024-8851

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as ad…

Fix: 1.0.77+
Fix from $1,600 2025-05-15
Appointment Booking Calendar CRITICAL 9.8
CVE-2025-46247

Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Proper…

Fix: 1.3.93+
Fix from $2,300 2025-04-22
Appointment Booking Calendar HIGH 8.8
CVE-2025-46241

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This iss…

Fix: 1.3.93+
Fix from $1,950 2025-04-22
Form Builder Cp MEDIUM 6.5
CVE-2024-13680

The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL_APPEAR_HERE' shortcode in al…

Fix: 1.2.42+
Fix from $1,600 2025-01-24
Appointment Booking Calendar HIGH 7.5
CVE-2024-12274

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public …

Fix: 1.1.23+
Fix from $1,950 2025-01-13
Calculated Fields Form MEDIUM 5.3
CVE-2024-12601

The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlim…

Fix: 5.2.64+
Fix from $1,600 2024-12-17
Wp Time Slots Booking Form HIGH 7.2
CVE-2023-23895

Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form allows Exploiting Incorrectly Configured Access Control Security Levels.…

Fix: 1.1.83+
Fix from $1,950 2024-12-09
Smart Image Gallery MEDIUM 6.8
CVE-2024-3632

The Smart Image Gallery WordPress plugin before 1.0.19 does not have CSRF check in place when updating its settings, which could allow attackers to m…

Fix: 1.0.19+
Fix from $1,600 2024-07-13
Wp Time Slots Booking Form CRITICAL 9.8
CVE-2024-35735

Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.11.

Fix: 1.2.12+
Fix from $2,300 2024-06-10
Wp Time Slots Booking Form HIGH 7.5
CVE-2024-33543

Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06.

Fix: 1.2.07+
Fix from $1,950 2024-06-09
Wp Time Slots Booking Form MEDIUM 6.1
CVE-2024-35734

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople WP Time Slots Booking Form al…

Fix: 1.2.11+
Fix from $1,600 2024-06-08
Music Store MEDIUM 6.5
CVE-2024-36082

SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrati…

Fix: 1.1.14+
Fix from $1,600 2024-06-07
Contact Form Email MEDIUM 6.5
CVE-2023-48318

Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affec…

Fix: 1.3.42+
Fix from $1,600 2024-06-04
Cp Contact Form With Paypal HIGH 8.8
CVE-2023-27460

Missing Authorization vulnerability in CodePeople, paypaldev CP Contact Form with Paypal allows Functionality Misuse.This issue affects CP Contact Fo…

Fix: 1.3.35+
Fix from $1,950 2024-06-03
Contact Form Email MEDIUM 5.3
CVE-2024-31302

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from…

Fix: 1.3.44+
Fix from $1,600 2024-04-10
Calculated Fields Form MEDIUM 6.1
CVE-2024-29759

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Calculated Fields Form allows Reflec…

Fix: 1.2.55+
Fix from $1,600 2024-03-27
Google Maps Cp HIGH 8.8
CVE-2023-25039

Missing Authorization vulnerability in CodePeople Google Maps CP.This issue affects Google Maps CP: from n/a through 1.0.43.

Fix: after 1.0.43
Fix from $1,950 2024-03-25
Appointment Booking Calendar HIGH 8.8
CVE-2024-0856

The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged …

Fix: 1.3.83+
Fix from $1,950 2024-03-20
Calculated Fields Form MEDIUM 6.1
CVE-2024-2020

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href parameter in all versions up to, …

Fix: 5.1.57+
Fix from $1,600 2024-03-13
Calculated Fields Form MEDIUM 5.4
CVE-2024-0963

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULATED_FIELDS shortcode in all v…

Fix: after 1.2.52
Fix from $1,600 2024-02-02
Wp Time Slots Booking Form HIGH 8.8
CVE-2022-41790

Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76.

Fix: after 1.1.76
Fix from $1,950 2024-01-17
Calculated Fields Form MEDIUM 5.4
CVE-2023-51517

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: fro…

Fix: after 1.2.28
Fix from $1,600 2023-12-29
Contact Form Email MEDIUM 5.4
CVE-2023-2718

The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vu…

Fix: 1.3.38+
Fix from $1,600 2023-06-12
Cp Appointment Calendar CRITICAL 9.8
CVE-2015-10099

A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dex_proce…

Fix: after 1.1.5
Fix from $2,300 2023-04-10
Polls Cp CRITICAL 9.8
CVE-2014-125091

A vulnerability has been found in codepeople cp-polls Plugin 1.0.1 on WordPress and classified as critical. This vulnerability affects unknown code o…

Patch available
Fix from $2,300 2023-03-04
Appointment Booking Calendar HIGH 8.8
CVE-2022-43482

Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.

Fix: 1.3.70+
Fix from $1,950 2022-11-18
Appointment Booking Calendar HIGH 7.8
CVE-2020-9372EPSS 9%

The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to …

Fix: 1.3.35+
Fix from $1,950 2020-03-04
Calculated Fields Form MEDIUM 5.4
CVE-2020-7228

The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These ca…

Fix: after 1.0.353
Fix from $1,600 2020-01-22