Codemenschen develops a gift-voucher platform where vulnerabilities center on application-layer authorization and input-handling defects, specifically SQL injection and missing authorization controls. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codemenschen over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16159CRITICAL The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request. | Aug 30, 2018 | 9.8 | 71 | NO | YES |
CVE-2023-28662CRITICAL The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_ | Mar 22, 2023 | 9.8 | 63 | NO | YES |
CVE-2026-57415HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codemenschen Gift Vouchers gift-voucher allows Stored XSS.This issue affects G | Jul 13, 2026 | 7.1 | 29 | NO | NO |
CVE-2026-57412MEDIUM Missing Authorization vulnerability in Codemenschen Gift Vouchers gift-voucher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gift Vouch | Jul 13, 2026 | 6.5 | 27 | NO | NO |
CVE-2024-13520MEDIUM The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability | Feb 20, 2025 | 5.3 | 16 | NO | NO |
CVE-2024-32436MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Codemenschen Gift Vouchers.This issue affects Gift Vouchers: from n/a through 4.4.0. | Apr 15, 2024 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codemenschen.
Media articles that mention a CVE ID that affects a product developed by Codemenschen — matched by CVE ID, not by vendor name.