Codepeople
Codepeople Contact Form Email: vulnerabilidades y CVE
Codepeople Contact Form Email tiene 11 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-32483 | Media (6.5) | 0.33% | — | 25 mar 2026 | Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through… |
| CVE-2025-24727 | Media (4.8) | 0.31% | — | 24 ene 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Contact Form Email contact-form-to-email allows Stored XSS.This issue affects Contact Form Email: from n/a… |
| CVE-2023-48318 | Media (6.5) | 0.31% | — | 4 jun 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affects Contact Form Email: from n/a through 1.3.41. |
| CVE-2023-28494 | Media (4.3) | 0.31% | — | 4 jun 2024 | Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31. |
| CVE-2024-31302 | Media (5.3) | 0.47% | — | 10 abr 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from n/a through 1.3.44. |
| CVE-2023-5955 | Media (4.8) | 0.46% | — | 11 dic 2023 | The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2023-2718 | Media (5.4) | 0.51% | — | 12 jun 2023 | The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability. |
| CVE-2021-42361 | Media (4.8) | 0.62% | — | 17 nov 2021 | The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which… |
| CVE-2018-20964 | Alta (8.8) | 0.68% | — | 13 ago 2019 | The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF. |
| CVE-2018-20963 | Media (6.1) | 0.92% | — | 13 ago 2019 | The contact-form-to-email plugin before 1.2.66 for WordPress has XSS. |
| CVE-2019-9646 | Media (6.1) | 1.4% | — | 10 mar 2019 | The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area." |
Otros productos de Codepeople
Calculated Fields Form · 14Appointment Booking Calendar · 12WP Time Slots Booking Form · 12Booking Calendar Contact Form · 7Polls CP · 5CP Contact Form With Paypal · 5CP Polls · 4Music Store · 4CP Multi View Event Calendar · 4Form Builder CP · 4Appointment Hour Booking · 2Payment Form FOR Paypal PRO · 2