Extension WordPress

Vulnérabilités SP Project & Document Manager

Cette page rassemble les failles publiées pour SP Project & Document Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.

24Vulnérabilités
5Critiques
16Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de SP Project & Document Manager

24 fiches

CVE-2026-10737 Élevée · 7,5
SP Project & Document Manager

SP Project & Document Manager <= 4.71 – Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function

The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in all versions up to, and including, 4.71. This makes it possible for unauthenticated…

Versions affectées

*-4.71

Correctif

Non indiqué

Publication

03/06/2026

CVE-2024-37224 Moyenne · 4,3
SP Project & Document Manager

SP Project & Document Manager <= 4.71 – Authenticated (Subscriber+) Directory Traversal

The SP Project & Document Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.71. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform actions on…

Versions affectées

*-4.71

Correctif

Non indiqué

Publication

21/06/2024

CVE-2024-31118 Moyenne · 6,4
SP Project & Document Manager

SP Project & Document Manager <= 4.70 – Missing Authorization Stored Cross-Site Scripting

The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check function in versions up to, and including, 4.70. This makes it possible for authenticated attackers, with subscriber-level access…

Versions affectées

*-4.70

Correctif

Non indiqué

Publication

29/03/2024

CVE-2024-24868 Élevée · 8,8
SP Project & Document Manager

SP Project & Document Manager <= 4.69 – Authenticated (Contributor+) SQL Injection via Shortcode

The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via the sp_cdm_display_project_shortcode_show function in versions up to, and including, 4.69 due to insufficient escaping on the user supplied parameter and lack of sufficient…

Versions affectées

*-4.69

Correctif

4.70

Publication

02/02/2024

CVE-2023-36530 Moyenne · 4,4
SP Project & Document Manager

SP Project & Document Manager <= 4.67 – Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings

The SP Project & Document Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 4.67 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-4.67

Correctif

4.68

Publication

30/06/2023

CVE-2023-3063 Élevée · 8,8
SP Project & Document Manager

SP Project & Document Manager <= 4.67 – Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change

The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass…

Versions affectées

*-4.67

Correctif

4.68

Publication

29/06/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités