School Management <= 93.1.0 - Unauthenticated Insecure Direct Object Reference
medium
The School Management plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 93.1.0. This is due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 93.1.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2026
CVE-2025-15657 on NVD →
School Management [school-management] <= 1.93.1 (02-07-2025) (unfixed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Mojoomla School Management allows Upload a Web Shell to a Web Server.This issue affects School Management: from n/a through 1.93.1 (02-07-2025).
- Affected:
- up to 1.93.1 (02-07-2025)
- Fix:
- No patched version reported
- Disclosed:
- Aug 31, 2025
CVE-2025-31100 on NVD →
School Management [school-management] <= 93.2.0 (unfixed)
unknown
[en] Missing Authorization vulnerability in Mojoomla School Management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects School Management: from n/a through 93.2.0.
- Affected:
- up to 93.2.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 26, 2025
CVE-2025-48108 on NVD →
School Management [school-management] <= 93.1.0 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus – Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord Post Plus – Supports Unlimited Channels: from n/a through 1.0.2.
- Affected:
- up to 93.1.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 20, 2025
CVE-2025-49896 on NVD →
School Management [school-management] <= 93.2.0 (unfixed)
unknown
[en] The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters across multiple AJAX action in all versions up to, and including, 93.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. T...
- Affected:
- up to 93.2.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 16, 2025
CVE-2024-12612 on NVD →
School Management [school-management] <= 93.2.0 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy.Com allows Object Injection.This issue affects ServerBuddy by PluginBuddy.Com: from n/a through 1.0.5.
- Affected:
- up to 93.2.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 16, 2025
CVE-2025-49895 on NVD →
School Management System for Wordpress <= 93.2.0 - Unauthenticated SQL Injection
high
The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters across multiple AJAX action in all versions up to, and including, 93.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This m...
- CVSS:
- 7.5
- Affected:
- up to 93.2.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2025
CVE-2024-12612 on NVD →
School Management System <= 93.2.0 - Authenticated (Student+) Arbitrary File Upload
high
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the homework.php file in all versions up to, and including, 93.2.0. This makes it possible for authenticated attackers, with Student-level access and above, to upload arbitrary...
- CVSS:
- 8.8
- Affected:
- up to 93.2.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2025
CVE-2025-6079 on NVD →
School Management <= 93.2.0 - Authenticated (Support staff+) SQL Injection
medium
The School Management plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 93.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with support staff-level acces...
- CVSS:
- 6.5
- Affected:
- up to 93.2.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2025
CVE-2025-49898 on NVD →
School Management <= 93.1.0 - Unauthenticated Insecure Direct Object Reference
medium
The School Management System for Wordpress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 93.1.0 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 93.1.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2025
CVE-2025-49896 on NVD →
School Management <= 93.2.0 - Missing Authorization
medium
The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 93.2.0. This makes it possible for authenticated attackers, with Custom-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 93.2.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2025
CVE-2025-48108 on NVD →
School Management [school-management] <= 93.2.0 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xolluteon Dropshix allows DOM-Based XSS.This issue affects Dropshix: from n/a through 4.0.14.
- Affected:
- up to 93.2.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2025
CVE-2025-49898 on NVD →
School Management <= 1.93.1 (02-07-2025) - Authenticated (Student+) Arbitrary File Upload
critical
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.93.1 (02-07-2025). This makes it possible for authenticated attackers, with Custom-level access and above, to upload arbitrary files on the...
- CVSS:
- 9.8
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Aug 12, 2025
CVE-2025-31100 on NVD →
School Management System for Wordpress <= 93.1.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update
high
The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, a...
- CVSS:
- 8.8
- Affected:
- up to 93.1.0
- Fixed in:
- 1.93.1 (02-07-2025)
- Disclosed:
- Jul 17, 2025
CVE-2025-3740 on NVD →
School Management [school-management] <= 92.0.0 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla School Management allows Reflected XSS. This issue affects School Management: from n/a through 92.0.0.
- Affected:
- up to 92.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-47574 on NVD →
School Management <= 92.0.0 - Reflected Cross-Site Scripting
medium
The School Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 92.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu...
- CVSS:
- 6.1
- Affected:
- up to 92.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 18, 2025
CVE-2025-47574 on NVD →
School Management <= 93.2.0 - Authenticated (Support Staff+) Privilege Escalation
medium
The School Management plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 93.2.0. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for authenticated attackers, with support staff-level access and above, to elevate th...
- CVSS:
- 6.3
- Affected:
- up to 93.2.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 17, 2025
CVE-2025-15656 on NVD →
School Management [school-management] <= 92.0.0 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows Blind SQL Injection. This issue affects School Management: from n/a through 92.0.0.
- Affected:
- up to 92.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 17, 2025
CVE-2025-47573 on NVD →
School Management [school-management] <= 93.0.0 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in mojoomla School Management allows PHP Local File Inclusion. This issue affects School Management: from n/a through 93.0.0.
- Affected:
- up to 93.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 17, 2025
CVE-2025-47572 on NVD →
School Management <= 93.0.0 - Authenticated (Student+) Local File Inclusion
high
The School Management plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 93.0.0. This makes it possible for authenticated attackers, with student-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files....
- CVSS:
- 8.8
- Affected:
- up to 93.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 12, 2025
CVE-2025-47572 on NVD →
School Management <= 92.0.0 - Unauthenticated SQL Injection
high
The School Management plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL quer...
- CVSS:
- 7.5
- Affected:
- up to 92.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 11, 2025
CVE-2025-47573 on NVD →
School Management [school-management] <= 92.0.0 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 92.0.0.
- Affected:
- up to 92.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 23, 2025
CVE-2025-47575 on NVD →
School Management [school-management] <= 92.0.0 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla School Management allows Reflected XSS. This issue affects School Management: from n/a through 92.0.0.
- Affected:
- up to 92.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 23, 2025
CVE-2025-47613 on NVD →
School Management <= 92.0.0 - Authenticated (Subscriber+) SQL Injection
medium
The School Management plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access a...
- CVSS:
- 6.5
- Affected:
- up to 92.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 20, 2025
CVE-2025-47575 on NVD →
School Management <= 92.0.0 - Reflected Cross-Site Scripting
medium
The School Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 92.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu...
- CVSS:
- 6.1
- Affected:
- up to 92.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 20, 2025
CVE-2025-47613 on NVD →
School Management [school-management] < 93.0.0
unknown
[en] The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the mj_smgt_view_stu...
- Affected:
- up to 93.0.0
- Fixed in:
- 93.0.0
- Disclosed:
- Mar 7, 2025
CVE-2024-12609 on NVD →
School Management [school-management] <= 93.0.0 (unfixed)
unknown
[en] The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and 'mj_smgt_remove_category_new' AJAX actions in all versions up to, and including, 93.0.0. This makes it possible for unauthenticated attack...
- Affected:
- up to 93.0.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 7, 2025
CVE-2024-12610 on NVD →
School Management [school-management] < 93.0.0
unknown
[en] The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exist...
- Affected:
- up to 93.0.0
- Fixed in:
- 93.0.0
- Disclosed:
- Mar 7, 2025
CVE-2024-12607 on NVD →
School Management [school-management] <= 93.0.0 (unfixed)
unknown
[en] The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 93.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- Affected:
- up to 93.0.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 7, 2025
CVE-2024-12611 on NVD →
School Management System for Wordpress <= 93.0.0 - Authenticated (Student+) Account Takeover and Privilege Escalation
high
The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email and password through the mj_smgt_update_...
- CVSS:
- 8.8
- Affected:
- up to 93.0.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 6, 2025
CVE-2024-9658 on NVD →
School Management System for Wordpress <= 92.0.0 - Authenticated (Subscriber+) SQL Injection via 'mj_smgt_show_event_task'
medium
The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing S...
- CVSS:
- 6.5
- Affected:
- up to 92.0.0
- Fixed in:
- 93.0.0
- Disclosed:
- Mar 6, 2025
CVE-2024-12607 on NVD →
School Management System for Wordpress <= 92.0.0 - Authenticated (Student+) SQL Injection via 'view-attendance'
medium
The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the mj_smgt_view_student_...
- CVSS:
- 6.5
- Affected:
- up to 92.0.0
- Fixed in:
- 93.0.0
- Disclosed:
- Mar 6, 2025
CVE-2024-12609 on NVD →
School Management System for Wordpress <= 93.0.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
medium
The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and 'mj_smgt_remove_category_new' AJAX actions in all versions up to, and including, 93.0.0. This makes it possible for unauthenticated attackers t...
- CVSS:
- 5.3
- Affected:
- up to 93.0.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 6, 2025
CVE-2024-12610 on NVD →
School Management System for Wordpress <= 93.0.0 - Reflected Cross-Site Scripting
medium
The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 93.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 5.3
- Affected:
- up to 93.0.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 6, 2025
CVE-2024-12611 on NVD →
School Management [school-management] < 92.0.0
unknown
[en] The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_load_documets_new() and mj_smgt_load_documets() functions in all versions up to, and including, 91.5.0. This makes it possible for authenticated attackers, with...
- Affected:
- up to 92.0.0
- Fixed in:
- 92.0.0
- Disclosed:
- Nov 23, 2024
CVE-2024-9660 on NVD →
School Management [school-management] < 92.0.0
unknown
[en] The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function in all versions up to, and including, 91.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files...
- Affected:
- up to 92.0.0
- Fixed in:
- 92.0.0
- Disclosed:
- Nov 23, 2024
CVE-2024-9659 on NVD →
School Management <= 91.5.0 - Unauthenticated Arbitrary File Upload
critical
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function in all versions up to, and including, 91.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on t...
- CVSS:
- 9.8
- Affected:
- up to 91.5.0
- Fixed in:
- 92.0.0
- Disclosed:
- Nov 22, 2024
CVE-2024-9659 on NVD →
School Management <= 91.5.0 - Authenticated (Student+) Arbitrary File Upload
high
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_load_documets_new() and mj_smgt_load_documets() functions in all versions up to, and including, 91.5.0. This makes it possible for authenticated attackers, with Stud...
- CVSS:
- 8.8
- Affected:
- up to 91.5.0
- Fixed in:
- 92.0.0
- Disclosed:
- Nov 22, 2024
CVE-2024-9660 on NVD →
School Management System for Wordpress <= 56.0 - Cross-Site Request Forgery
high
The School Management System for Wordpress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 56.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to inject malicious code via forged request granted they can tric...
- CVSS:
- 8.8
- Affected:
- up to 57.0
- Fixed in:
- 57.0
- Disclosed:
- Jul 13, 2019
School Management [school-management] < 57.0
unknown
The School Management System for Wordpress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 56.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to inject malicious code via forged request granted they can tric...
- Affected:
- up to 57.0
- Fixed in:
- 57.0
- Disclosed:
- Jul 13, 2019
School Management [school-management] < 57.0
unknown
Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) vulnerabilities found by m0ns7er in WordPress School Management plugin (versions < 57.0).
- Affected:
- up to 57.0
- Fixed in:
- 57.0
- Disclosed:
- Jul 13, 2019
Mojoomla School Management System (Unspecified Version) - Authenticated (Student+) SQL Injection
high
The Mojoomla School Management System plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in unknown versions due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with student-...
- CVSS:
- 8.8
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Sep 26, 2017
CVE-2017-14843 on NVD →
School Management [school-management] <= 93.0.0 (unfixed)
unknown
- Affected:
- up to 93.0.0
- Fix:
- No patched version reported
CVE-2024-9658 on NVD →
School Management [school-management] < 57.0
unknown
CSRF and Stored XSS (Cross Site Scripting)
Edit (WPScanTeam):
June 17th - Issue Reported to Envato
June 17th - Envato Support confirmed they are investigating the issue
June 28th - New version released, fixing the XSS but not the CSRF. Envato notified
July 5th - Demo fixed, new version to be released
July 11th...
- Affected:
- up to 57.0
- Fixed in:
- 57.0
School Management [school-management] < 1.93.1 (02-07-2025)
unknown
- Affected:
- up to 1.93.1 (02-07-2025)
- Fixed in:
- 1.93.1 (02-07-2025)
CVE-2025-3740 on NVD →
School Management [school-management] <= 93.2.0 (unfixed)
unknown
- Affected:
- up to 93.2.0
- Fix:
- No patched version reported
CVE-2025-6079 on NVD →