Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2024-37224 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document Manager.This issue … Sp Project \& Document Manager after 4.71 Fix from $1,6002024-07-09 MEDIUM 6.5 CVE-2024-3749 The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download file… Sp Project \& Document Manager 4.71+ Fix from $1,6002024-05-15 MEDIUM 6.5 CVE-2024-3748 The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user… Sp Project \& Document Manager after 4.71 Fix from $1,6002024-05-15 HIGH 8.8 CVE-2024-24868 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This … Sp Project \& Document Manager 4.70+ Fix from $1,9502024-02-28 HIGH 8.8 CVE-2023-36677 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allow… Sp Project \& Document Manager after 4.67 Fix from $1,9502023-11-03 HIGH 8.8 CVE-2023-3063 The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. Thi… Sp Project \& Document Manager after 4.67 Fix from $1,9502023-06-30 MEDIUM 6.1 CVE-2022-34857 Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress Sp Project \& Document Manager 4.62+ Fix from $1,6002022-08-22 MEDIUM 6.5 CVE-2022-1551 The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access… Sp Project \& Document Manager 4.58+ Fix from $1,6002022-07-25 HIGH 8.8 CVE-2021-4225 The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attem… Sp Project \& Document Manager 4.24+ Fix from $1,9502022-04-25 HIGH 7.5 CVE-2021-38324 The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows … Sp Rental Manager after 1.5.3 Fix from $1,9502021-09-09 MEDIUM 6.1 CVE-2021-38315 The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via the from and to parameters in … Sp Project \& Document Manager after 4.25 Fix from $1,6002021-08-16 HIGH 8.8 CVE-2021-24347EPSS 54% The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other si… Sp Project \& Document Manager 4.22+ Fix from $1,9502021-06-14 HIGH 7.5 CVE-2014-9178 Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manag… Sp Project \& Document Manager after 2.4.1 Fix from $1,9502014-12-02