Extension WordPress
Vulnérabilités SP Project & Document Manager
Cette page rassemble les failles publiées pour SP Project & Document Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de SP Project & Document Manager
24 fiches
SP Project & Document Manager <= 4.71 – Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in all versions up to, and including, 4.71. This makes it possible for unauthenticated…
*-4.71
Non indiqué
03/06/2026
SP Project & Document Manager <= 4.71 – Authenticated (Subscriber+) Directory Traversal
The SP Project & Document Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.71. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform actions on…
*-4.71
Non indiqué
21/06/2024
SP Project & Document Manager <= 4.70 – Authenticated (Subscriber+) Arbitrary Folder Name Update
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category AJAX action in all versions up to, and including, 4.70. This makes it…
*-4.70
Non indiqué
07/05/2024
SP Project & Document Manager <= 4.69 – Missing Authorization
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.69. This makes it possible for authenticated attackers, with…
*-4.69
Non indiqué
29/04/2024
SP Project & Document Manager <= 4.71 – Insecure Direct Object Reference to Information Exposure
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.71 via the cdm_file_list AJAX action due to missing validation on a user controlled key.…
*-4.71
Non indiqué
24/04/2024
SP Project & Document Manager <= 4.71 – Insecure Direct Object Reference
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.71 via the sp_cdm_link_save_embed AJAX action to missing validation on the 'user_id' user controlled key.…
*-4.71
Non indiqué
24/04/2024
SP Project & Document Manager <= 4.71 – Authenticated (Author+) SQL Injeciton
The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to, and including, 4.71 due to insufficient escaping on the user supplied parameter and lack of…
*-4.71
Non indiqué
16/04/2024
SP Project & Document Manager <= 4.70 – Missing Authorization Stored Cross-Site Scripting
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check function in versions up to, and including, 4.70. This makes it possible for authenticated attackers, with subscriber-level access…
*-4.70
Non indiqué
29/03/2024
SP Project & Document Manager <= 4.69 – Authenticated (Contributor+) SQL Injection via Shortcode
The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via the sp_cdm_display_project_shortcode_show function in versions up to, and including, 4.69 due to insufficient escaping on the user supplied parameter and lack of sufficient…
*-4.69
4.70
02/02/2024
SP Project & Document Manager <= 4.67 – Authenticated (Subscriber+) SQL Injection
The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via an unknownparameter in versions up to, and including, 4.67 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-4.67
4.68
30/06/2023
SP Project & Document Manager <= 4.67 – Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings
The SP Project & Document Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 4.67 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.67
4.68
30/06/2023
SP Project & Document Manager <= 4.67 – Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass…
*-4.67
4.68
29/06/2023
SP Project & Document Manager <= 4.59 – Reflected Cross-Site Scripting
Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin
*-4.59
4.62
10/08/2022
SP Project & Document Manager <= 4.59 – Reflected Cross-Site Scripting
The SP Project & Document Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 4.59 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.59
4.62
10/08/2022
SP Project & Document Manager <= 4.57 – Sensitive File Disclosure
The SP Project & Document Manager WordPress plugin through 4.57 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
*-4.57
4.58
28/06/2022
SP Project & Document Manager <= 4.56 – Cross-Site Request Forgery and Cross-Site Scripting
The SP Project & Document Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.56. This is due to missing or incorrect nonce validation in several functions. Furthermore, in several instances…
*-4.56
4.57
17/06/2022
SP Project & Document Manager <= 4.25 – Reflected Cross-Site Scripting
The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via the from and to parameters in the ~/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and…
*-4.25
4.26
16/08/2021
SP Project & Document Manager <= 4.23 – Subscriber+ Arbitrary File Upload
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from…
[*, 4.24)
4.24
28/07/2021
SP Project & Document Manager <= 4.21 – Authenticated Shell Upload
The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking…
[*, 4.22)
4.22
25/05/2021
SP Projects & Document Manager <= 2.5.9.5 – Cross-Site Scripting
The SP Projects & Document Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.9.5 due to insufficient input sanitization and output escaping on several parameters. This makes it possible for attackers…
*-2.6.0.0
2.6.1.4
07/03/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.