Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

codepeople — Vulnerabilities & Security Advisories 82

Browse all 82 CVE security advisories affecting codepeople. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Codepeople operates as a provider of enterprise software solutions, primarily focusing on human resources and payroll management systems. Historical security audits reveal a significant volume of vulnerabilities, with seventy CVEs currently on record, indicating persistent weaknesses in their development lifecycle. The most prevalent flaw classes include remote code execution and cross-site scripting, which often stem from inadequate input validation and improper session management. Additionally, privilege escalation vulnerabilities have been frequently exploited, allowing unauthorized users to access sensitive administrative functions. These issues suggest a lack of rigorous security testing during the software development phase. While no single catastrophic data breach has been widely publicized as a direct result of these specific CVEs, the high count of critical and high-severity findings poses a substantial risk to client data integrity. Organizations relying on these platforms must prioritize patching and implement strict access controls to mitigate the identified risks effectively.

CVE ID Title CVSS Severity Published
CVE-2026-93624 WordPress Music Player for WooCommerce plugin <= 1.9.1 - PHP Object Injection vulnerability — Music Player for WooCommerce CWE-502 7.2 High 2026-09-30
CVE-2026-95529 WordPress Calculated Fields Form plugin <= 5.5.1.1 - Cross Site Scripting (XSS) vulnerability — Calculated Fields Form CWE-79 7.1 High 2026-09-23
CVE-2026-78283 WordPress Music Player for WooCommerce plugin <= 1.8.9 - Cross Site Scripting (XSS) vulnerability — Music Player for WooCommerce CWE-79 7.1 High 2026-08-27
CVE-2026-78281 WordPress CP Media Player plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability — CP Media Player CWE-79 7.1 High 2026-08-27
CVE-2026-66679 WordPress Appointment Hour Booking plugin <= 1.5.91 - Broken Access Control vulnerability — Appointment Hour Booking CWE-1284 6.5 Medium 2026-08-18
CVE-2026-65514 WordPress Appointment Hour Booking plugin <= 1.5.86 - Cross Site Scripting (XSS) vulnerability — Appointment Hour Booking CWE-79 6.5 Medium 2026-07-23
CVE-2026-57670 WordPress Google Maps CP plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability — Google Maps CP CWE-79 7.1 High 2026-07-02
CVE-2026-12113 Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure — Appointment Booking Calendar CWE-862 4.3 Medium 2026-07-01
CVE-2026-13335 CodePeople Post Map for Google Maps <= 1.2.6 - Authenticated (Contributor +) Stored Cross-Site Scripting via 'cpm_point' Post Meta — CodePeople Post Map for Google Maps CWE-79 6.4 Medium 2026-06-27
CVE-2026-12111 Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter — Appointment Booking Calendar CWE-200 4.3 Medium 2026-06-18
CVE-2026-48882 WordPress WP Time Slots Booking Form plugin <= 1.2.50 - SQL Injection vulnerability — WP Time Slots Booking Form CWE-89 8.5 High 2026-06-15
CVE-2026-40791 WordPress WP Time Slots Booking Form plugin <= 1.2.46 - Cross Site Scripting (XSS) vulnerability — WP Time Slots Booking Form CWE-79 7.1 High 2026-06-15
CVE-2026-6810 Booking Calendar Contact Form <= 1.2.63 - Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover — Booking Calendar Contact Form CWE-639 5.3 Medium 2026-04-24
CVE-2026-32483 WordPress Contact Form Email plugin <= 1.3.63 - Broken Access Control vulnerability — Contact Form Email CWE-862 6.5 Medium 2026-03-25
CVE-2026-25465 WordPress CP Multi View Event Calendar plugin <= 1.4.36 - Cross Site Scripting (XSS) vulnerability — CP Multi View Event Calendar CWE-79 6.5 Medium 2026-03-25
CVE-2026-32432 WordPress WP Time Slots Booking Form plugin <= 1.2.42 - Broken Access Control vulnerability — WP Time Slots Booking Form CWE-862 5.3 Medium 2026-03-13
CVE-2026-32433 WordPress CP Contact Form with Paypal plugin <= 1.3.61 - SQL Injection vulnerability — CP Contact Form with Paypal CWE-89 8.5 High 2026-03-13
CVE-2026-3986 Calculated Fields Form <= 5.4.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Settings — Calculated Fields Form CWE-79 6.4 Medium 2026-03-13
CVE-2026-25368 WordPress Calculated Fields Form plugin <= 5.4.4.1 - Broken Access Control vulnerability — Calculated Fields Form CWE-862 6.5 Medium 2026-02-19
CVE-2026-1083 Appointment Hour Booking – Booking Calendar <= 1.5.60 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration — Appointment Hour Booking – Booking Calendar CWE-79 4.4 Medium 2026-01-28
CVE-2026-0684 CP Image Store with Slideshow <= 1.1.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Product Import — CP Image Store with Slideshow CWE-863 4.3 Medium 2026-01-13
CVE-2025-68850 WordPress Sell Downloads plugin <= 1.1.12 - Broken Access Control vulnerability — Sell Downloads CWE-862 7.5 High 2026-01-05
CVE-2025-68569 WordPress WP Time Slots Booking Form plugin <= 1.2.39 - Broken Access Control vulnerability — WP Time Slots Booking Form CWE-862 6.5 Medium 2025-12-24
CVE-2025-10019 WordPress Contact Form Email plugin <= 1.3.60 - Insecure Direct Object References (IDOR) vulnerability — Contact Form Email CWE-639 6.5 Medium 2025-12-18
CVE-2025-13318 Booking Calendar Contact Form <= 1.2.60 - Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter — Booking Calendar Contact Form CWE-862 5.3 Medium 2025-11-22
CVE-2025-13384 CP Contact Form with PayPal <= 1.3.56 - Missing Authorization to Unauthenticated Arbitrary Payment Confirmation — CP Contact Form with PayPal CWE-862 7.5 High 2025-11-22
CVE-2025-13317 Appointment Booking Calendar <= 1.3.96 - Missing Authorization to Arbitrary Booking Confirmation via 'cpabc_ipncheck' Parameter — Appointment Booking Calendar CWE-862 5.3 Medium 2025-11-22
CVE-2025-64369 WordPress Contact Form Email plugin <= 1.3.58 - Broken Access Control vulnerability — Contact Form Email CWE-862 6.5 Medium 2025-11-13
CVE-2025-64261 WordPress Appointment Booking Calendar plugin <= 1.3.95 - Broken Access Control vulnerability — Appointment Booking Calendar CWE-862 5.4 Medium 2025-11-13
CVE-2025-58009 WordPress CP Multi View Event Calendar plugin <= 1.4.35 - Broken Access Control vulnerability — CP Multi View Event Calendar CWE-862 3.8 Low 2025-09-22

This page lists every published CVE security advisory associated with codepeople. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.