Skip to content
Noroxi

smartypantsplugins records

15 published records for vendor smartypantsplugins.

All records

15 records
  • SP Project & Document Manager <2 4.22 - Authenticated Shell Upload

    HighCVSS 8.8WeaponizedEPSS 54%

    smartypantsplugins · sp project \& document managerJun 14, 2021

  • CVE-2021-4225
    36Monitor

    SP Project & Document Manager < 4.24 - Subscriber+ Shell Upload

    HighCVSS 8.8No exploitEPSS 2%

    smartypantsplugins · sp project \& document managerApr 25, 2022

  • CVE-2023-3063
    35Monitor

    SP Project & Document Manager <= 4.67 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change

    HighCVSS 8.8No exploitEPSS 1%

    smartypantsplugins · sp project \& document managerJun 29, 2023

  • WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to SQL Injection

    HighCVSS 8.8No exploitEPSS 1%

    smartypantsplugins · sp project \& document managerNov 3, 2023

  • WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL Injection

    HighCVSS 8.8No exploitEPSS 1%

    smartypantsplugins · sp project \& document managerFeb 28, 2024

  • CVE-2014-9178
    31Monitor

    Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-docum

    HighCVSS 7.5Proof of conceptEPSS 5%

    smartypantsplugins · sp project \& document managerDec 2, 2014

  • SP Rental Manager <= 1.5.3 Unauthenticated SQL Injection

    HighCVSS 7.5No exploitEPSS 2%

    smartypantsplugins · sp rental managerSep 9, 2021

  • CVE-2022-1551
    26Monitor

    SP Project & Document Manager < 4.58 - Sensitive File Disclosure

    MediumCVSS 6.5No exploitEPSS 1%

    smartypantsplugins · sp project \& document managerJul 25, 2022

  • WordPress SP Project & Document Manager plugin <= 4.71 - Directory Traversal vulnerability

    MediumCVSS 6.5No exploitEPSS 1%

    smartypantsplugins · sp project \& document managerJul 9, 2024

  • CVE-2024-3749
    26Monitor

    SP Project & Document Manager <= 4.71 - Subscriber+ File Download via IDOR

    MediumCVSS 6.5No exploitEPSS 1%

    smartypantsplugins · sp project \& document managerMay 15, 2024

  • CVE-2024-3748
    26Monitor

    SP Project & Document Manager <= 4.71 - Data Update via IDOR

    MediumCVSS 6.5No exploitEPSS 0%

    smartypantsplugins · sp project \& document managerMay 15, 2024

  • SP Project & Document Manager <= 4.25 Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    smartypantsplugins · sp project \& document managerAug 16, 2021

  • WordPress SP Project & Document Manager plugin <= 4.59 - Reflected Cross-Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 1%

    smartypantsplugins · sp project \& document managerAug 22, 2022

  • WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    smartypantsplugins · sp project \& document managerAug 10, 2023

  • CVE-2013-3529
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote

    MediumCVSS 4.3Proof of conceptEPSS 5%

    wordpress · wordpressMay 10, 2013