Product
smartypantsplugins sp project \& document manager
13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-37224
CVE-2024-3749
CVE-2024-3748
CVE-2024-24868
CVE-2023-36677
CVE-2023-36530
CVE-2023-3063
CVE-2022-34857
CVE-2022-1551
CVE-2021-4225
CVE-2021-38315
CVE-2021-24347
CVE-2014-9178
<= 4.71
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document
< 4.71
The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to vie
<= 4.71
The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to m
< 4.70
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Doc
<= 4.67
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Doc
<= 4.67
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versio
<= 4.67
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and i
< 4.62
Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress
< 4.58
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could
< 4.24
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload file
<= 4.25
The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via the from an
< 4.22
The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to preve
<= 2.4.1
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-cl