Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

codepeople — Vulnerabilities & Security Advisories 82

Browse all 82 CVE security advisories affecting codepeople. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Codepeople operates as a provider of enterprise software solutions, primarily focusing on human resources and payroll management systems. Historical security audits reveal a significant volume of vulnerabilities, with seventy CVEs currently on record, indicating persistent weaknesses in their development lifecycle. The most prevalent flaw classes include remote code execution and cross-site scripting, which often stem from inadequate input validation and improper session management. Additionally, privilege escalation vulnerabilities have been frequently exploited, allowing unauthorized users to access sensitive administrative functions. These issues suggest a lack of rigorous security testing during the software development phase. While no single catastrophic data breach has been widely publicized as a direct result of these specific CVEs, the high count of critical and high-severity findings poses a substantial risk to client data integrity. Organizations relying on these platforms must prioritize patching and implement strict access controls to mitigate the identified risks effectively.

CVE ID Title CVSS Severity Published
CVE-2025-48231 WordPress Booking Calendar Contact Form plugin <= 1.2.58 - Cross Site Scripting (XSS) Vulnerability — Booking Calendar Contact Form CWE-79 6.5 Medium 2025-07-04
CVE-2025-50025 WordPress CP Polls plugin <= 1.0.81 - Cross Site Scripting (XSS) vulnerability — CP Polls CWE-79 5.9 Medium 2025-06-20
CVE-2025-49332 WordPress WP Time Slots Booking Form plugin <= 1.2.30 - Cross Site Request Forgery (CSRF) Vulnerability — WP Time Slots Booking Form CWE-352 4.3 Medium 2025-06-06
CVE-2025-49291 WordPress Calculated Fields Form plugin <= 5.3.58 - Cross Site Request Forgery (CSRF) Vulnerability — Calculated Fields Form CWE-352 4.3 Medium 2025-06-06
CVE-2025-47472 WordPress Music Player for WooCommerce plugin <= 1.5.1 - Broken Access Control Vulnerability — Music Player for WooCommerce CWE-862 5.4 Medium 2025-05-07
CVE-2025-46247 WordPress Appointment Booking Calendar plugin <= 1.3.92 - Broken Access Control Vulnerability — Appointment Booking Calendar CWE-862 5.3 Medium 2025-04-22
CVE-2025-46241 WordPress Appointment Booking Calendar plugin <= 1.3.92 - CSRF to SQL Injection vulnerability — Appointment Booking Calendar CWE-352 8.2 High 2025-04-22
CVE-2025-39562 WordPress Payment Form for PayPal Pro plugin <= 1.1.72 - Cross Site Scripting (XSS) Vulnerability — Payment Form for PayPal Pro CWE-79 5.9 Medium 2025-04-17
CVE-2024-13758 CP Contact Form with PayPal <= 1.3.52 - Cross-Site Request Forgery — CP Contact Form with PayPal CWE-352 6.5 Medium 2025-01-30
CVE-2025-24626 WordPress Music Store – WordPress eCommerce Plugin <= 1.1.19 - Reflected Cross Site Scripting (XSS) vulnerability — Music Store CWE-79 7.1 High 2025-01-27
CVE-2025-24723 WordPress Booking Calendar Contact Form Plugin <= 1.2.55 - Stored Cross Site Scripting (XSS) vulnerability — Booking Calendar Contact Form CWE-79 5.9 Medium 2025-01-24
CVE-2025-24727 WordPress Contact Form to Email Plugin <= 1.3.52 - Cross Site Scripting (XSS) vulnerability — Contact Form Email CWE-79 5.9 Medium 2025-01-24
CVE-2025-24672 WordPress Form Builder CP Plugin <= 1.2.41 - SQL Injection vulnerability — Form Builder CP CWE-89 8.5 High 2025-01-24
CVE-2024-13680 Form Builder CP <= 1.2.41 - Authenticated (Contributor+) SQL Injection — Form Builder CP CWE-89 6.5 Medium 2025-01-24
CVE-2023-45649 WordPress Appointment Hour Booking plugin <= 1.4.23 - Broken Access Control vulnerability — Appointment Hour Booking CWE-862 5.3 Medium 2025-01-02
CVE-2024-12601 Calculated Fields Form <= 5.2.63 - Denial of Service — Calculated Fields Form CWE-400 5.3 Medium 2024-12-17
CVE-2023-23814 WordPress Calendar Event Multi View plugin <= 1.4.13 - Broken Access Control vulnerability — CP Multi View Event Calendar CWE-862 3.8 Low 2024-12-09
CVE-2023-23895 WordPress WP Time Slots Booking Form plugin <= 1.1.82 - Broken Access Control vulnerability — WP Time Slots Booking Form CWE-862 4.7 Medium 2024-12-09
CVE-2023-25037 WordPress Booking Calendar Contact Form plugin <= 1.2.34 - Broken Access Control vulnerability — Booking Calendar Contact Form CWE-862 4.3 Medium 2024-12-09
CVE-2024-9940 Calculated Fields Form <= 5.2.45 - HTML Injection — Calculated Fields Form CWE-75 5.3 Medium 2024-10-17
CVE-2024-47297 WordPress Polls CP plugin <= 1.0.74 - Reflected Cross Site Scripting (XSS) vulnerability — CP Polls CWE-79 7.1 High 2024-10-06
CVE-2024-35735 WordPress WP Time Slots Booking Form plugin <= 1.2.11 - Broken Access Control vulnerability — WP Time Slots Booking Form CWE-862 5.3 Medium 2024-06-10
CVE-2024-33543 WordPress WP Time Slots Booking Form plugin <= 1.2.06 - Broken Access Control vulnerability — WP Time Slots Booking Form CWE-862 7.5 High 2024-06-09
CVE-2024-35734 WordPress WP Time Slots Booking Form plugin <= 1.2.10 - Cross Site Scripting (XSS) vulnerability — WP Time Slots Booking Form CWE-79 7.1 High 2024-06-08
CVE-2024-36082 WordPress plugin Music Store 安全漏洞 — Music Store - WordPress eCommerce 7.2 - 2024-06-07
CVE-2023-48318 WordPress Contact Form Email plugin <= 1.3.41 - Captcha Bypass vulnerability — Contact Form Email CWE-307 5.3 Medium 2024-06-04
CVE-2023-28494 WordPress Contact Form Email plugin <= 1.3.31 - Missing Authorization Leading To Feedback Submission Vulnerability — Contact Form Email CWE-862 4.3 Medium 2024-06-04
CVE-2023-28492 WordPress Calendar Event Multi View plugin <= 1.4.10 - Missing Authorization Leading To Feedback Submission vulnerability — CP Multi View Event Calendar CWE-862 4.3 Medium 2024-06-03
CVE-2023-26523 WordPress Calculated Fields Form plugin <= 1.1.120 - Missing Authorization Leading To Feedback Submission Vulnerability — Calculated Fields Form CWE-862 4.3 Medium 2024-06-03
CVE-2023-26521 WordPress Search in Place plugin <= 1.0.104 - Missing Authorization Leading To Feedback Submission vulnerability — Search in Place CWE-862 4.3 Medium 2024-06-03

This page lists every published CVE security advisory associated with codepeople. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.