Codebangers maintains a time-tracking application, All-in-One Time Clock Lite, with a narrow but focused vulnerability footprint centered on web-facing input-handling issues. The observed weakness class reflects cross-site scripting vulnerabilities characteristic of web applications where user input is not properly neutralized before inclusion in page output. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codebangers over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44594MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Codebangers All in One Time Clock Lite plugin <= 1.3.320 versions. | Apr 23, 2023 | 4.8 | 19 | NO | NO |
CVE-2025-46513MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Codebangers All in One Time Clock Lite aio-time-clock-lite allows Cross Site Request Forgery.This issue affects All in One Time C | Apr 24, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codebangers.
Media articles that mention a CVE ID that affects a product developed by Codebangers — matched by CVE ID, not by vendor name.