Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Soplanning HIGH 8.8
CVE-2025-62730

SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users.…

Fix: 1.55.00+
Fix from $1,950 2025-11-20
Soplanning HIGH 7.5
CVE-2025-62294

SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attac…

Fix: 1.55.00+
Fix from $1,950 2025-11-20
Soplanning MEDIUM 5.4
CVE-2025-62293

SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Status functionality an authentica…

Fix: 1.55.00+
Fix from $1,600 2025-11-20
Soplanning MEDIUM 5.4
CVE-2025-62295

SOPlanning is vulnerable to Stored XSS in /groupe_form endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into webs…

Fix: 1.55.00+
Fix from $1,600 2025-11-20
Soplanning MEDIUM 5.4
CVE-2025-62296

SOPlanning is vulnerable to Stored XSS in /taches endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, …

Fix: 1.55.00+
Fix from $1,600 2025-11-20
Soplanning MEDIUM 5.4
CVE-2025-62297

SOPlanning is vulnerable to Stored XSS in /projets endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website,…

Fix: 1.55.00+
Fix from $1,600 2025-11-20
Soplanning MEDIUM 5.4
CVE-2025-62729

SOPlanning is vulnerable to Stored XSS in /status endpoint. Malicious attacker with an account can inject arbitrary HTML and JS into website, which w…

Fix: 1.55.00+
Fix from $1,600 2025-11-20
Soplanning MEDIUM 5.4
CVE-2025-41001

Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of proper validation of user inpu…

Mitigation only
Fix from $1,600 2025-11-10
Soplanning CRITICAL 9.8
CVE-2024-57169

A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to b…

No fix yet
Fix from $2,300 2025-03-18
Soplanning MEDIUM 6.5
CVE-2024-57170

SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attack…

No fix yet
Fix from $1,600 2025-03-18
Soplanning MEDIUM 6.5
CVE-2024-9573

SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to sen…

Fix: 1.45+
Fix from $1,600 2024-10-07
Soplanning MEDIUM 6.5
CVE-2024-9574

SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit …

Fix: 1.45+
Fix from $1,600 2024-10-07
Soplanning MEDIUM 5.4
CVE-2024-9571

Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/xajax_server…

Fix: 1.45+
Fix from $1,600 2024-10-07
Soplanning MEDIUM 5.4
CVE-2024-9572

Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/groupe_save.…

Fix: 1.45+
Fix from $1,600 2024-10-07
Soplanning CRITICAL 9.8
CVE-2024-27114

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, …

Fix: 1.52.02+
Fix from $2,300 2024-09-11
Soplanning CRITICAL 9.8
CVE-2024-27115

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker ca…

Fix: 1.52.02+
Fix from $2,300 2024-09-11
Soplanning CRITICAL 9.8
CVE-2024-27112

A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use thi…

Fix: 1.52.02+
Fix from $2,300 2024-09-11
Soplanning CRITICAL 9.8
CVE-2024-27113

An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view se…

Fix: 1.52.02+
Fix from $2,300 2024-09-11
Soplanning CRITICAL 9.8
CVE-2020-13963

SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The …

Fix: 1.47+
Fix from $2,300 2021-03-21
Soplanning MEDIUM 5.3
CVE-2020-25867

SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentica…

Fix: 1.47+
Fix from $1,600 2020-10-07
Soplanning MEDIUM 5.4
CVE-2020-15597

SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field.

Fix: after 1.46.01
Fix from $1,600 2020-08-11
Soplanning MEDIUM 5.4
CVE-2020-9338

SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.

No fix yet
Fix from $1,600 2020-02-22
Soplanning MEDIUM 5.4
CVE-2020-9339

SOPlanning 1.45 allows XSS via the Name or Comment to status.php.

No fix yet
Fix from $1,600 2020-02-22
Soplanning HIGH 7.5
CVE-2020-9268

SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.

No fix yet
Fix from $1,950 2020-02-18
Soplanning HIGH 7.2
CVE-2020-9269

SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as demonstrated by export_ical.…

No fix yet
Fix from $1,950 2020-02-18
Soplanning MEDIUM 6.5
CVE-2020-9266

SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.

No fix yet
Fix from $1,600 2020-02-18
Soplanning MEDIUM 6.5
CVE-2020-9267

SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.

No fix yet
Fix from $1,600 2020-02-18
Soplanning HIGH 8.8
CVE-2019-20179

SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.

Fix: after 1.45
Fix from $1,950 2020-01-09
Soplanning CRITICAL 9.8
CVE-2014-8673EPSS 12%

Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPP…

Fix: after 1.32
Fix from $2,300 2020-01-07
Soplanning MEDIUM 5.4
CVE-2014-8674

Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and m…

Fix: 1.33+
Fix from $1,600 2020-01-06