Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

codepeople — Vulnerabilities & Security Advisories 82

Browse all 82 CVE security advisories affecting codepeople. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Codepeople operates as a provider of enterprise software solutions, primarily focusing on human resources and payroll management systems. Historical security audits reveal a significant volume of vulnerabilities, with seventy CVEs currently on record, indicating persistent weaknesses in their development lifecycle. The most prevalent flaw classes include remote code execution and cross-site scripting, which often stem from inadequate input validation and improper session management. Additionally, privilege escalation vulnerabilities have been frequently exploited, allowing unauthorized users to access sensitive administrative functions. These issues suggest a lack of rigorous security testing during the software development phase. While no single catastrophic data breach has been widely publicized as a direct result of these specific CVEs, the high count of critical and high-severity findings poses a substantial risk to client data integrity. Organizations relying on these platforms must prioritize patching and implement strict access controls to mitigate the identified risks effectively.

CVE ID Title CVSS Severity Published
CVE-2024-32720 WordPress Appointment Hour Booking plugin <= 1.4.56 - Captcha Bypass vulnerability — Appointment Hour Booking CWE-307 5.3 Medium 2024-05-17
CVE-2024-24873 WordPress Polls CP plugin <= 1.0.71 - Polls Limitation Bypass vulnerability — CP Polls CWE-799 5.3 Medium 2024-05-17
CVE-2024-24874 WordPress Polls CP plugin <= 1.0.71 - Content Injection vulnerability — CP Polls CWE-80 5.3 Medium 2024-05-17
CVE-2024-31941 WordPress CP Media Player plugin <= 1.1.3 - Cross Site Request Forgery (CSRF) vulnerability — CP Media Player CWE-352 5.4 Medium 2024-04-15
CVE-2024-31302 WordPress Contact Form Email plugin <= 1.3.44 - Sensitive Data Exposure vulnerability — Contact Form Email CWE-200 5.3 Medium 2024-04-10
CVE-2024-29759 WordPress Calculated Fields Form plugin <= 1.2.54 - Reflected Cross Site Scripting (XSS) vulnerability — Calculated Fields Form CWE-79 7.1 High 2024-03-27
CVE-2023-25039 WordPress Google Maps CP plugin <= 1.0.43 - Missing Authorization Leading To Feedback Submission Vulnerability — Google Maps CP CWE-862 4.3 Medium 2024-03-25
CVE-2024-2020 Calculated Fields Form Professional <= 5.1.56 - Unauthenticated Stored Cross-Site Scripting — Calculated Fields Form CWE-79 7.2 High 2024-03-13
CVE-2024-0963 Calculated Fields Form <= 1.2.52 - Authenticated (Contributor+) Stored Cross-Site Scripting — Calculated Fields Form CWE-79 6.4 Medium 2024-02-02
CVE-2022-41790 WordPress WP Time Slots Booking Form Plugin <= 1.1.76 is vulnerable to Broken Access Control — WP Time Slots Booking Form CWE-862 4.3 Medium 2024-01-17
CVE-2023-6446 Calculated Fields Form <= 1.2.40 - Authenticated (Admin+) Stored Cross-Site Scripting — Calculated Fields Form CWE-87 4.4 Medium 2024-01-11
CVE-2023-51517 WordPress Calculated Fields Form Plugin <= 1.2.28 is vulnerable to Open Redirection — Calculated Fields Form CWE-601 4.1 Medium 2023-12-29
CVE-2023-41732 WordPress CP Blocks Plugin <= 1.0.20 is vulnerable to Cross Site Request Forgery (CSRF) — CP Blocks CWE-352 5.4 Medium 2023-10-06
CVE-2023-36384 WordPress Booking Calendar Contact Form Plugin <= 1.2.40 is vulnerable to Cross Site Scripting (XSS) — Booking Calendar Contact Form CWE-79 7.1 High 2023-07-18
CVE-2023-23971 WordPress WP Time Slots Booking Form Plugin <= 1.1.81 is vulnerable to Cross Site Scripting (XSS) — WP Time Slots Booking Form CWE-79 5.9 Medium 2023-04-06
CVE-2014-125091 codepeople cp-polls Plugin cp-admin-int-message-list.inc.php sql injection — cp-polls Plugin CWE-89 4.7 Medium 2023-03-04
CVE-2022-3427 Corner Ad <= 1.0.56 - Cross-Site Request Forgery — Corner Ad CWE-352 8.8 High 2022-12-15
CVE-2022-4036 Appointment Hour Booking <= 1.3.72 - CAPTCHA Bypass — Appointment Hour Booking – Booking Calendar CWE-804 5.3 Medium 2022-11-29
CVE-2022-4035 Appointment Hour Booking <= 1.3.72 - Unauthenticated iFrame Injection via Appointment Form — Appointment Hour Booking – Booking Calendar CWE-79 7.2 High 2022-11-29
CVE-2022-4034 Appointment Hour Booking <= 1.3.72 - CSV Injection — Appointment Hour Booking – Booking Calendar CWE-1236 5.8 Medium 2022-11-29
CVE-2022-43482 WordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerability — Appointment Booking Calendar (WordPress plugin) CWE-862 4.3 Medium 2022-11-18
CVE-2022-41692 WordPress Appointment Hour Booking plugin <= 1.3.71 - Missing Authorization vulnerability — Appointment Hour Booking (WordPress plugin) CWE-862 4.3 Medium 2022-11-18

This page lists every published CVE security advisory associated with codepeople. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.