Codeamp's vulnerability footprint centers on its search and filter functionality, where the recurring exposure reflects web-application input-handling weaknesses, specifically cross-site scripting through improper neutralization of user-supplied content. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codeamp over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4467MEDIUM The Search & Filter WordPress plugin before 1.2.16 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users wi | Jan 23, 2023 | 5.4 | 20 | NO | NO |
CVE-2025-48099MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Code Amp Search & Filter search-filter allows Cross Site Request Forgery.This issue affects Search & Filter: from n/a through <= | Oct 22, 2025 | 4.7 | 18 | NO | NO |
CVE-2024-6481MEDIUM The Search & Filter Pro WordPress plugin before 2.5.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cro | Aug 8, 2024 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codeamp.
Media articles that mention a CVE ID that affects a product developed by Codeamp — matched by CVE ID, not by vendor name.