smartypantsplugins records
15 published records for vendor smartypantsplugins.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 6.7%
- Pre-auth RCE
- 1
- With a fix record
- 20%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-178 Improper Handling of Case Sensitivity1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2021-24347Weaponized | SP Project & Document Manager <2 4.22 - Authenticated Shell Uploadsmartypantsplugins · sp project \& document manager · CWE-178 | High8.8 | — | 54.1% | Jun 14, 2021 |
36Monitor | CVE-2021-4225No exploit | SP Project & Document Manager < 4.24 - Subscriber+ Shell Uploadsmartypantsplugins · sp project \& document manager · CWE-434 | High8.8 | — | 1.7% | Apr 25, 2022 |
35Monitor | CVE-2023-3063No exploit | SP Project & Document Manager <= 4.67 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Changesmartypantsplugins · sp project \& document manager · CWE-639 | High8.8 | — | 0.7% | Jun 29, 2023 |
35Monitor | CVE-2023-36677No exploit | WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to SQL Injectionsmartypantsplugins · sp project \& document manager · CWE-89 | High8.8 | — | 0.7% | Nov 3, 2023 |
35Monitor | CVE-2024-24868No exploit | WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL Injectionsmartypantsplugins · sp project \& document manager · CWE-89 | High8.8 | — | 0.5% | Feb 28, 2024 |
31Monitor | CVE-2014-9178Proof of concept | Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-documsmartypantsplugins · sp project \& document manager · CWE-89 | High7.5 | — | 4.6% | Dec 2, 2014 |
31Monitor | CVE-2021-38324No exploit | SP Rental Manager <= 1.5.3 Unauthenticated SQL Injectionsmartypantsplugins · sp rental manager · CWE-89 | High7.5 | — | 1.8% | Sep 9, 2021 |
26Monitor | CVE-2022-1551No exploit | SP Project & Document Manager < 4.58 - Sensitive File Disclosuresmartypantsplugins · sp project \& document manager · CWE-425 | Medium6.5 | — | 1.0% | Jul 25, 2022 |
26Monitor | CVE-2024-37224No exploit | WordPress SP Project & Document Manager plugin <= 4.71 - Directory Traversal vulnerabilitysmartypantsplugins · sp project \& document manager · CWE-22 | Medium6.5 | — | 0.6% | Jul 9, 2024 |
26Monitor | CVE-2024-3749No exploit | SP Project & Document Manager <= 4.71 - Subscriber+ File Download via IDORsmartypantsplugins · sp project \& document manager · CWE-639 | Medium6.5 | — | 0.5% | May 15, 2024 |
26Monitor | CVE-2024-3748No exploit | SP Project & Document Manager <= 4.71 - Data Update via IDORsmartypantsplugins · sp project \& document manager · CWE-639 | Medium6.5 | — | 0.4% | May 15, 2024 |
24Monitor | CVE-2021-38315No exploit | SP Project & Document Manager <= 4.25 Reflected Cross-Site Scriptingsmartypantsplugins · sp project \& document manager · CWE-79 | Medium6.1 | — | 0.9% | Aug 16, 2021 |
24Monitor | CVE-2022-34857No exploit | WordPress SP Project & Document Manager plugin <= 4.59 - Reflected Cross-Site Scripting (XSS) vulnerabilitysmartypantsplugins · sp project \& document manager · CWE-79 | Medium6.1 | — | 0.6% | Aug 22, 2022 |
19Monitor | CVE-2023-36530No exploit | WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to Cross Site Scripting (XSS)smartypantsplugins · sp project \& document manager · CWE-79 | Medium4.8 | — | 0.4% | Aug 10, 2023 |
18Monitor | CVE-2013-3529Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote wordpress · wordpress · CWE-79 | Medium4.3 | — | 4.6% | May 10, 2013 |
- CVE-2021-2434751Plan
SP Project & Document Manager <2 4.22 - Authenticated Shell Upload
HighCVSS 8.8WeaponizedEPSS 54%smartypantsplugins · sp project \& document managerJun 14, 2021
- CVE-2021-422536Monitor
SP Project & Document Manager < 4.24 - Subscriber+ Shell Upload
HighCVSS 8.8No exploitEPSS 2%smartypantsplugins · sp project \& document managerApr 25, 2022
- CVE-2023-306335Monitor
SP Project & Document Manager <= 4.67 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change
HighCVSS 8.8No exploitEPSS 1%smartypantsplugins · sp project \& document managerJun 29, 2023
- CVE-2023-3667735Monitor
WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to SQL Injection
HighCVSS 8.8No exploitEPSS 1%smartypantsplugins · sp project \& document managerNov 3, 2023
- CVE-2024-2486835Monitor
WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL Injection
HighCVSS 8.8No exploitEPSS 1%smartypantsplugins · sp project \& document managerFeb 28, 2024
- CVE-2014-917831Monitor
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-docum
HighCVSS 7.5Proof of conceptEPSS 5%smartypantsplugins · sp project \& document managerDec 2, 2014
- CVE-2021-3832431Monitor
SP Rental Manager <= 1.5.3 Unauthenticated SQL Injection
HighCVSS 7.5No exploitEPSS 2%smartypantsplugins · sp rental managerSep 9, 2021
- CVE-2022-155126Monitor
SP Project & Document Manager < 4.58 - Sensitive File Disclosure
MediumCVSS 6.5No exploitEPSS 1%smartypantsplugins · sp project \& document managerJul 25, 2022
- CVE-2024-3722426Monitor
WordPress SP Project & Document Manager plugin <= 4.71 - Directory Traversal vulnerability
MediumCVSS 6.5No exploitEPSS 1%smartypantsplugins · sp project \& document managerJul 9, 2024
- CVE-2024-374926Monitor
SP Project & Document Manager <= 4.71 - Subscriber+ File Download via IDOR
MediumCVSS 6.5No exploitEPSS 1%smartypantsplugins · sp project \& document managerMay 15, 2024
- CVE-2024-374826Monitor
SP Project & Document Manager <= 4.71 - Data Update via IDOR
MediumCVSS 6.5No exploitEPSS 0%smartypantsplugins · sp project \& document managerMay 15, 2024
- CVE-2021-3831524Monitor
SP Project & Document Manager <= 4.25 Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%smartypantsplugins · sp project \& document managerAug 16, 2021
- CVE-2022-3485724Monitor
WordPress SP Project & Document Manager plugin <= 4.59 - Reflected Cross-Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 1%smartypantsplugins · sp project \& document managerAug 22, 2022
- CVE-2023-3653019Monitor
WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%smartypantsplugins · sp project \& document managerAug 10, 2023
- CVE-2013-352918Monitor
Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote
MediumCVSS 4.3Proof of conceptEPSS 5%wordpress · wordpressMay 10, 2013