Browse all 5 CVE security advisories affecting Codeless. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Codeless enables application development through visual programming interfaces, allowing users to create applications without writing code. Historically, it has been associated with vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and insecure default configurations. The platform's reliance on third-party plugins and automated code generation has introduced additional security risks. While no major public security incidents have been widely reported, the five documented CVEs highlight persistent concerns around sanitization and access control in its visual development environment.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-53786 | WordPress Cowidgets – Elementor Addons plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability — Cowidgets – Elementor AddonsCWE-79 | 6.5 | Medium | 2024-11-30 |
| CVE-2024-37419 | WordPress Cowidgets – Elementor Addons plugin <= 1.1.1 - Local File Inclusion vulnerability — Cowidgets – Elementor AddonsCWE-22 | 7.5 | High | 2024-07-09 |
| CVE-2024-35782 | WordPress Cowidgets – Elementor Addons plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability — Cowidgets – Elementor AddonsCWE-79 | 6.5 | Medium | 2024-06-04 |
This page lists every published CVE security advisory associated with Codeless. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.