Home/Product/smartypantsplugins sp project \& document manager
Product

smartypantsplugins sp project \& document manager

13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-37224
<= 4.71
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document
7.5HIGH
CVE-2024-3749
< 4.71
The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to vie
6.5MEDIUM
CVE-2024-3748
<= 4.71
The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to m
6.5MEDIUM
CVE-2024-24868
< 4.70
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Doc
8.5HIGH
CVE-2023-36677
<= 4.67
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Doc
8.3HIGH
CVE-2023-36530
<= 4.67
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versio
5.9MEDIUM
CVE-2023-3063
<= 4.67
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and i
8.8HIGH
CVE-2022-34857
< 4.62
Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress
6.1MEDIUM
CVE-2022-1551
< 4.58
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could
6.5MEDIUM
CVE-2021-4225
< 4.24
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload file
8.8HIGH
CVE-2021-38315
<= 4.25
The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via the from an
6.1MEDIUM
CVE-2021-24347
< 4.22
The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to preve
8.8HIGH
CVE-2014-9178
<= 2.4.1
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-cl
threatengine.sh