Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

codesolz — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting codesolz. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CodeSolz develops software solutions with a primary focus on enterprise applications and web platforms. Historically, their products have been susceptible to multiple vulnerability classes, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, contributing to their 12 recorded CVEs. The organization has faced scrutiny for inconsistent patch management and delayed security updates, with several critical vulnerabilities remaining unaddressed for extended periods. While no major public security incidents have been documented, the accumulation of CVEs suggests potential systemic weaknesses in their development lifecycle and security practices.

CVE IDTitleCVSSSeverityPublished
CVE-2026-3369 Better Find and Replace – AI-Powered Suggestions <= 1.7.9 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title — Better Find and Replace – AI-Powered SuggestionsCWE-79 5.4 Medium2026-04-16
CVE-2025-9334 Better Find and Replace <= 1.7.7 - Authenticated (Subscriber+) Limited Code Injection — Better Find and Replace – AI-Powered SuggestionsCWE-94 8.8 High2025-11-08
CVE-2025-12360 Better Find and Replace <= 1.7.7 - Missing Authorization — Better Find and Replace – AI-Powered SuggestionsCWE-285 4.3 Medium2025-11-06
CVE-2025-53466 WordPress Better Find and Replace Plugin <= 1.7.6 - Cross Site Scripting (XSS) Vulnerability — Better Find and ReplaceCWE-79 5.9 Medium2025-09-22
CVE-2025-50028 WordPress Ultimate Push Notifications plugin <= 1.2.0 - Broken Access Control Vulnerability — Ultimate Push NotificationsCWE-862 6.5 Medium2025-07-16
CVE-2025-31561 WordPress Ultimate Push Notifications plugin <= 1.2.0 - SQL Injection vulnerability — Ultimate Push NotificationsCWE-89 8.5 High2025-04-01
CVE-2025-31548 WordPress Ultimate Push Notifications plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) vulnerability — Ultimate Push NotificationsCWE-79 7.1 High2025-04-01
CVE-2025-26541 WordPress Bitcoin / AltCoin Payment Gateway for WooCommerce plugin <= 1.7.6 - Reflected Cross Site Scripting (XSS) vulnerability — Bitcoin / AltCoin Payment Gateway for WooCommerceCWE-79 7.1 High2025-03-26
CVE-2025-26535 WordPress Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop plugin <= 1.7.6 - SQL Injection vulnerability — Bitcoin / AltCoin Payment Gateway for WooCommerceCWE-89 9.3 Critical2025-03-03
CVE-2025-24734 WordPress Better Find and Replace plugin <= 1.6.7 - Privilege Escalation vulnerability — Better Find and ReplaceCWE-862 8.8 High2025-01-27
CVE-2024-39636 WordPress Better Find and Replace plugin <= 1.6.1 - PHP Object Injection vulnerability — Better Find and ReplaceCWE-502 8.3 High2024-08-01
CVE-2023-25460 WordPress Easy Ad Manager Plugin <= 1.0.0 is vulnerable to Cross Site Scripting (XSS) — Easy Ad ManagerCWE-79 5.9 Medium2023-05-12

This page lists every published CVE security advisory associated with codesolz. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.