Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sp Project \& Document Manager MEDIUM 6.5
CVE-2024-37224

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document Manager.This issue …

Fix: after 4.71
Fix from $1,600 2024-07-09
Sp Project \& Document Manager MEDIUM 6.5
CVE-2024-3749

The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download file…

Fix: 4.71+
Fix from $1,600 2024-05-15
Sp Project \& Document Manager MEDIUM 6.5
CVE-2024-3748

The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user…

Fix: after 4.71
Fix from $1,600 2024-05-15
Sp Project \& Document Manager HIGH 8.8
CVE-2024-24868

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This …

Fix: 4.70+
Fix from $1,950 2024-02-28
Sp Project \& Document Manager HIGH 8.8
CVE-2023-36677

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allow…

Fix: after 4.67
Fix from $1,950 2023-11-03
Sp Project \& Document Manager HIGH 8.8
CVE-2023-3063

The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. Thi…

Fix: after 4.67
Fix from $1,950 2023-06-30
Sp Project \& Document Manager MEDIUM 6.1
CVE-2022-34857

Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress

Fix: 4.62+
Fix from $1,600 2022-08-22
Sp Project \& Document Manager MEDIUM 6.5
CVE-2022-1551

The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access…

Fix: 4.58+
Fix from $1,600 2022-07-25
Sp Project \& Document Manager HIGH 8.8
CVE-2021-4225

The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attem…

Fix: 4.24+
Fix from $1,950 2022-04-25
Sp Rental Manager HIGH 7.5
CVE-2021-38324

The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows …

Fix: after 1.5.3
Fix from $1,950 2021-09-09
Sp Project \& Document Manager MEDIUM 6.1
CVE-2021-38315

The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via the from and to parameters in …

Fix: after 4.25
Fix from $1,600 2021-08-16
Sp Project \& Document Manager HIGH 8.8
CVE-2021-24347EPSS 54%

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other si…

Fix: 4.22+
Fix from $1,950 2021-06-14
Sp Project \& Document Manager HIGH 7.5
CVE-2014-9178

Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manag…

Fix: after 2.4.1
Fix from $1,950 2014-12-02