Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Soplanning MEDIUM 5.4
CVE-2025-41001

Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of proper validation of user inpu…

Mitigation only
Fix from $1,600 2025-11-10
Soplanning CRITICAL 9.8
CVE-2024-57169

A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to b…

No fix yet
Fix from $2,300 2025-03-18
Soplanning MEDIUM 6.5
CVE-2024-57170

SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attack…

No fix yet
Fix from $1,600 2025-03-18
Soplanning MEDIUM 5.4
CVE-2020-9338

SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.

No fix yet
Fix from $1,600 2020-02-22
Soplanning MEDIUM 5.4
CVE-2020-9339

SOPlanning 1.45 allows XSS via the Name or Comment to status.php.

No fix yet
Fix from $1,600 2020-02-22
Soplanning HIGH 7.5
CVE-2020-9268

SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.

No fix yet
Fix from $1,950 2020-02-18
Soplanning HIGH 7.2
CVE-2020-9269

SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as demonstrated by export_ical.…

No fix yet
Fix from $1,950 2020-02-18
Soplanning MEDIUM 6.5
CVE-2020-9266

SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.

No fix yet
Fix from $1,600 2020-02-18
Soplanning MEDIUM 6.5
CVE-2020-9267

SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.

No fix yet
Fix from $1,600 2020-02-18