Filtered by vendor Codepeople
Subscribe
Search
Total
15 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-51517 | 1 Codepeople | 1 Calculated Fields Form | 2024-01-05 | N/A | 5.4 MEDIUM |
| URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28. | |||||
| CVE-2023-5955 | 1 Codepeople | 1 Contact Form Email | 2023-12-13 | N/A | 4.8 MEDIUM |
| The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |||||
| CVE-2021-42361 | 1 Codepeople | 1 Contact Form Email | 2021-11-18 | 2.1 LOW | 4.8 MEDIUM |
| The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.3.24. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled. | |||||
| CVE-2020-9371 | 1 Codepeople | 1 Appointment Booking Calendar | 2020-03-12 | 3.5 LOW | 4.8 MEDIUM |
| Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScript or HTML. | |||||
| CVE-2020-7228 | 1 Codepeople | 1 Calculated Fields Form | 2020-01-24 | 3.5 LOW | 5.4 MEDIUM |
| The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user. | |||||
| CVE-2016-10992 | 1 Codepeople | 1 Music Store | 2019-09-18 | 4.3 MEDIUM | 6.1 MEDIUM |
| The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from_year parameter. | |||||
| CVE-2014-10395 | 1 Codepeople | 1 Polls Cp | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list. | |||||
| CVE-2015-9346 | 1 Codepeople | 1 Polls Cp | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The cp-polls plugin before 1.0.5 for WordPress has XSS. | |||||
| CVE-2016-10908 | 1 Codepeople | 1 Booking Calendar Contact Form | 2019-08-21 | 4.3 MEDIUM | 6.1 MEDIUM |
| The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS. | |||||
| CVE-2019-14784 | 1 Codepeople | 1 Cp Contact Form With Paypal | 2019-08-20 | 4.3 MEDIUM | 6.1 MEDIUM |
| The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition. | |||||
| CVE-2018-20963 | 1 Codepeople | 1 Contact Form Email | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The contact-form-to-email plugin before 1.2.66 for WordPress has XSS. | |||||
| CVE-2019-14785 | 1 Codepeople | 1 Cp Contact Form With Paypal | 2019-08-15 | 3.5 LOW | 5.4 MEDIUM |
| The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter. | |||||
| CVE-2019-14791 | 1 Codepeople | 1 Appointment Booking Calendar | 2019-08-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter. | |||||
| CVE-2015-7666 | 1 Codepeople | 1 Payment Form For Paypal Pro | 2019-07-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the cal parameter. | |||||
| CVE-2019-9646 | 1 Codepeople | 1 Contact Form Email | 2019-03-12 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area." | |||||
