Filtered by vendor Codepeople
Subscriptions
Total
67 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2016-10916 | 1 Codepeople | 1 Appointment Booking Calendar | 2024-11-21 | N/A |
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319. | ||||
CVE-2016-10909 | 1 Codepeople | 1 Booking Calendar Contact Form | 2024-11-21 | N/A |
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection. | ||||
CVE-2016-10908 | 1 Codepeople | 1 Booking Calendar Contact Form | 2024-11-21 | N/A |
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS. | ||||
CVE-2015-9348 | 1 Codepeople | 1 Sell Downloads | 2024-11-21 | N/A |
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs. | ||||
CVE-2015-9346 | 1 Codepeople | 1 Polls Cp | 2024-11-21 | N/A |
The cp-polls plugin before 1.0.5 for WordPress has XSS. | ||||
CVE-2015-10099 | 1 Codepeople | 1 Cp Appointment Calendar | 2024-11-21 | 6.3 Medium |
A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dex_process_ready_to_go_appointment of the file dex_appointments.php. The manipulation of the argument itemnumber leads to sql injection. It is possible to initiate the attack remotely. The patch is named e29a9cdbcb0f37d887dd302a05b9e8bf213da01d. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-225351. | ||||
CVE-2014-10395 | 1 Codepeople | 1 Polls Cp | 2024-11-21 | N/A |
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list. |