Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Codepeople

First CVE: Mar 19, 2014Active for: 12 yearsTotal CVEs: 90
25.9
VTI Score
Low

Codepeople develops a focused suite of WordPress plugins and form-building solutions including Calculated Fields Form, Appointment Booking Calendar, Contact Form by Email, and Time Slots Booking Form that serve small-to-medium web publishers and service providers. The vendor's vulnerability profile concentrates around web-application input-handling and access-control flaws, with recurring weakness classes including cross-site scripting, SQL injection, missing authorization, and cross-site request forgery that are characteristic of plugin-based WordPress development. A meaningful share of disclosed vulnerabilities reach serious severity outcomes, reflecting the risk posture of publicly exposed form and calendar interfaces that process user input and manage booking or appointment data. Defenders deploying these plugins should prioritize keeping them current and restrict plugin administrative capabilities; live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
90
Total CVEs
More Total CVEs than 99% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Codepeople over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 19, 2014
12 years ago
Most Recent CVE
Jul 2, 2026
22 days ago

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (90 CVEs).

90 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-9372HIGH
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then coul
Mar 4, 20207.838NOYES
CVE-2026-57670HIGH
Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions.
Jul 2, 20267.131NONO
CVE-2026-48882HIGH
Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.
Jun 15, 20268.530NONO
CVE-2015-10099CRITICAL
A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dex_process_ready_to_go_appointment of t
Apr 10, 20239.830NONO
CVE-2014-125091CRITICAL
A vulnerability has been found in codepeople cp-polls Plugin 1.0.1 on WordPress and classified as critical. This vulnerability affects unknown code of the file cp-admin-int-message
Mar 4, 20239.830NONO
CVE-2020-9371MEDIUM
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to injec
Mar 4, 20204.828NOYES
CVE-2026-40791HIGH
Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions.
Jun 15, 20267.127NONO
CVE-2026-32433HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contact-form-with-paypal allows Blin
Mar 13, 20268.527NONO
CVE-2025-68569HIGH
Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This
Dec 24, 20258.827NONO
CVE-2025-46247CRITICAL
Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Properly Constrained by ACLs.This iss
Apr 22, 20259.827NONO
View all 90 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products90 CVEs
66%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.1%)
Network86 (95.6%)
Unknown3 (3.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low87 (96.7%)
High0 (0.0%)
Unknown3 (3.3%)
User Interaction
None39 (43.3%)
Unknown3 (3.3%)
Required48 (53.3%)
Privileges Required
Low25 (27.8%)
High17 (18.9%)
None45 (50.0%)
Unknown3 (3.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (90 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
2.2% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Codepeople.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Codepeople — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Codepeople's Products

View all 6 CNAs →

Top CWEs