Codebard operates a focused portfolio of web-based tools and plugins centered on content creator monetization and support infrastructure, including Patreon integration widgets and help-desk solutions. The recurring vulnerability signal across these products reflects application-layer input-handling issues, primarily cross-site scripting and cross-site request forgery, which are characteristic of web-facing form and widget handlers that process user-supplied data and authentication state. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codebard over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47765HIGH Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon plugin <= 2.1.9 versions. | Nov 22, 2023 | 8.8 | 24 | NO | NO |
CVE-2025-22760MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Reflected XSS.This issue | Jan 15, 2025 | 6.1 | 19 | NO | NO |
CVE-2023-30491MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon plugin <= 2.1.8 versions. | Aug 5, 2023 | 6.1 | 19 | NO | NO |
CVE-2024-33928MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon allows Reflected XSS | May 3, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-47524MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability (requires PHP 8.x) in CodeBard CodeBard's Patron Button and Widgets for Patreon plugin <= 2.1.9 versions. | Nov 14, 2023 | 6.1 | 18 | NO | NO |
CVE-2025-22757MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Stored XSS.This issue af | Jan 31, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-56222MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Cross Site Request Forgery.This issue affects CodeBard Help Desk: from n/a | Dec 31, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-48329MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard Fast Custom Social Share by CodeBard allows Stored XSS.This issue aff | Nov 30, 2023 | 4.8 | 17 | NO | NO |
CVE-2024-34807MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in CodeBard Fast Custom Social Share by CodeBard fast-custom-social-share-by-codebard.This issue affects Fast Custom Social Share by | May 17, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codebard.
Media articles that mention a CVE ID that affects a product developed by Codebard — matched by CVE ID, not by vendor name.