Vulnerabilities (CVE)

Filtered by vendor Smartypantsplugins Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-36530 1 Smartypantsplugins 1 Sp Project \& Document Manager 2023-08-16 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versions.
CVE-2022-1551 1 Smartypantsplugins 1 Sp Project \& Document Manager 2023-08-02 N/A 6.5 MEDIUM
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
CVE-2021-38315 1 Smartypantsplugins 1 Sp Project \& Document Manager 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via the from and to parameters in the ~/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.25.