Filtered by vendor Codepeople Subscriptions
Total 47 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2016-10909 1 Codepeople 1 Booking Calendar Contact Form 2024-11-21 N/A
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
CVE-2016-10908 1 Codepeople 1 Booking Calendar Contact Form 2024-11-21 N/A
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
CVE-2015-9348 1 Codepeople 1 Sell Downloads 2024-11-21 N/A
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
CVE-2015-9346 1 Codepeople 1 Polls Cp 2024-11-21 N/A
The cp-polls plugin before 1.0.5 for WordPress has XSS.
CVE-2015-10099 1 Codepeople 1 Cp Appointment Calendar 2024-11-21 6.3 Medium
A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dex_process_ready_to_go_appointment of the file dex_appointments.php. The manipulation of the argument itemnumber leads to sql injection. It is possible to initiate the attack remotely. The patch is named e29a9cdbcb0f37d887dd302a05b9e8bf213da01d. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-225351.
CVE-2014-10395 1 Codepeople 1 Polls Cp 2024-11-21 N/A
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
CVE-2024-9940 1 Codepeople 1 Calculated Fields Form 2024-10-18 5.3 Medium
The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views form submissions in their email.