Codeworkweb maintains a focused web application product portfolio centered on its Companion offering, which presents a modest attack surface rooted in application-layer input handling. The durable signal from observed disclosures centers on cross-site scripting vulnerabilities arising from improper neutralization of user input during web page generation, a recurring pattern in dynamic web applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codeworkweb over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67473HIGH Cross-Site Request Forgery (CSRF) vulnerability in codeworkweb CWW Companion cww-companion allows Cross Site Request Forgery.This issue affects CWW Companion: from n/a through <= 1 | Dec 9, 2025 | 8.8 | 26 | NO | NO |
CVE-2024-2130MEDIUM The CWW Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Module2 widget in all versions up to, and including, 1.2.7 due to insufficient input san | Mar 12, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codeworkweb.
Media articles that mention a CVE ID that affects a product developed by Codeworkweb — matched by CVE ID, not by vendor name.