SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function
high
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in all versions up to, and including, 4.71. This makes it possible for unauthenticated attackers to read file metadata and obtain download links for arbitrary files sto...
- CVSS:
- 7.5
- Affected:
- up to 4.71
- Fix:
- No patched version reported
- Disclosed:
- Jun 3, 2026
CVE-2026-10737 on NVD →
SP Project & Document Manager [sp-client-document-manager] <= 4.71 (unfixed + closed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.71.
- Affected:
- up to 4.71
- Fix:
- No patched version reported
- Disclosed:
- Jul 9, 2024
CVE-2024-37224 on NVD →
SP Project & Document Manager <= 4.71 - Authenticated (Subscriber+) Directory Traversal
medium
The SP Project & Document Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.71. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform actions on files outside of the originally intended directory.
- CVSS:
- 4.3
- Affected:
- up to 4.71
- Fix:
- No patched version reported
- Disclosed:
- Jun 21, 2024
CVE-2024-37224 on NVD →
SP Project & Document Manager [sp-client-document-manager] <= 4.71 (unfixed + closed)
unknown
[en] The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user
- Affected:
- up to 4.71
- Fix:
- No patched version reported
- Disclosed:
- May 15, 2024
CVE-2024-3749 on NVD →
SP Project & Document Manager [sp-client-document-manager] <= 4.71 (unfixed + closed)
unknown
[en] The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user
- Affected:
- up to 4.71
- Fix:
- No patched version reported
- Disclosed:
- May 15, 2024
CVE-2024-3748 on NVD →
SP Project & Document Manager [sp-client-document-manager] <= 4.70 (unfixed + closed)
unknown
[en] The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category AJAX action in all versions up to, and including, 4.70. This makes it possible for authenticated attackers, with subscriber-level access and above, to...
- Affected:
- up to 4.70
- Fix:
- No patched version reported
- Disclosed:
- May 9, 2024
CVE-2024-1693 on NVD →
SP Project & Document Manager <= 4.70 - Authenticated (Subscriber+) Arbitrary Folder Name Update
medium
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category AJAX action in all versions up to, and including, 4.70. This makes it possible for authenticated attackers, with subscriber-level access and above, to upda...
- CVSS:
- 4.3
- Affected:
- up to 4.70
- Fix:
- No patched version reported
- Disclosed:
- May 7, 2024
CVE-2024-1693 on NVD →
SP Project & Document Manager [sp-client-document-manager] <= 4.69 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.69.
- Affected:
- up to 4.69
- Fix:
- No patched version reported
- Disclosed:
- May 3, 2024
CVE-2024-33923 on NVD →
SP Project & Document Manager <= 4.69 - Missing Authorization
medium
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.69. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 4.69
- Fix:
- No patched version reported
- Disclosed:
- Apr 29, 2024
CVE-2024-33923 on NVD →
SP Project & Document Manager <= 4.71 - Insecure Direct Object Reference
medium
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.71 via the sp_cdm_link_save_embed AJAX action to missing validation on the 'user_id' user controlled key. This makes it possible for authenticated attackers, with subscriber-l...
- CVSS:
- 4.3
- Affected:
- up to 4.71
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2024
CVE-2024-3748 on NVD →
SP Project & Document Manager <= 4.71 - Insecure Direct Object Reference to Information Exposure
medium
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.71 via the cdm_file_list AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and a...
- CVSS:
- 4.3
- Affected:
- up to 4.71
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2024
CVE-2024-3749 on NVD →
SP Project & Document Manager [sp-client-document-manager] <= 4.71 (unfixed + closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.71.
- Affected:
- up to 4.71
- Fix:
- No patched version reported
- Disclosed:
- Apr 18, 2024
CVE-2024-32551 on NVD →
SP Project & Document Manager <= 4.71 - Authenticated (Author+) SQL Injeciton
critical
The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to, and including, 4.71 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...
- CVSS:
- 9.9
- Affected:
- up to 4.71
- Fix:
- No patched version reported
- Disclosed:
- Apr 16, 2024
CVE-2024-32551 on NVD →
SP Project & Document Manager <= 4.70 - Missing Authorization Stored Cross-Site Scripting
medium
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check function in versions up to, and including, 4.70. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject malicious web scripts into pages.
- CVSS:
- 6.4
- Affected:
- up to 4.70
- Fix:
- No patched version reported
- Disclosed:
- Mar 29, 2024
CVE-2024-31118 on NVD →
SP Project & Document Manager [sp-client-document-manager] < 4.70 (closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.69.
- Affected:
- up to 4.70
- Fixed in:
- 4.70
- Disclosed:
- Feb 28, 2024
CVE-2024-24868 on NVD →
SP Project & Document Manager <= 4.69 - Authenticated (Contributor+) SQL Injection via Shortcode
high
The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via the sp_cdm_display_project_shortcode_show function in versions up to, and including, 4.69 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it po...
- CVSS:
- 8.8
- Affected:
- up to 4.69
- Fixed in:
- 4.70
- Disclosed:
- Feb 2, 2024
CVE-2024-24868 on NVD →
SP Project & Document Manager [sp-client-document-manager] < 4.68 (closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affects SP Project & Document Manager: from n/a through 4.67.
- Affected:
- up to 4.68
- Fixed in:
- 4.68
- Disclosed:
- Nov 3, 2023
CVE-2023-36677 on NVD →
SP Project & Document Manager [sp-client-document-manager] < 4.68 (closed)
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versions.
- Affected:
- up to 4.68
- Fixed in:
- 4.68
- Disclosed:
- Aug 10, 2023
CVE-2023-36530 on NVD →
SP Project & Document Manager <= 4.67 - Authenticated (Subscriber+) SQL Injection
high
The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via an unknownparameter in versions up to, and including, 4.67 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attack...
- CVSS:
- 8.8
- Affected:
- up to 4.67
- Fixed in:
- 4.68
- Disclosed:
- Jun 30, 2023
CVE-2023-36677 on NVD →
SP Project & Document Manager <= 4.67 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings
medium
The SP Project & Document Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 4.67 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, t...
- CVSS:
- 4.4
- Affected:
- up to 4.67
- Fixed in:
- 4.68
- Disclosed:
- Jun 30, 2023
CVE-2023-36530 on NVD →
SP Project & Document Manager [sp-client-document-manager] < 4.68 (closed)
unknown
[en] The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authen...
- Affected:
- up to 4.68
- Fixed in:
- 4.68
- Disclosed:
- Jun 30, 2023
CVE-2023-3063 on NVD →
SP Project & Document Manager <= 4.67 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change
high
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticat...
- CVSS:
- 8.8
- Affected:
- up to 4.67
- Fixed in:
- 4.68
- Disclosed:
- Jun 29, 2023
CVE-2023-3063 on NVD →
SP Project & Document Manager [sp-client-document-manager] < 4.62 (closed)
unknown
[en] Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress
- Affected:
- up to 4.62
- Fixed in:
- 4.62
- Disclosed:
- Aug 22, 2022
CVE-2022-34857 on NVD →
SP Project & Document Manager <= 4.59 - Reflected Cross-Site Scripting
medium
Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress
- CVSS:
- 6.1
- Affected:
- up to 4.59
- Fixed in:
- 4.62
- Disclosed:
- Aug 10, 2022
CVE-2022-34857 on NVD →
SP Project & Document Manager <= 4.59 - Reflected Cross-Site Scripting
medium
The SP Project & Document Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 4.59 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 4.59
- Fixed in:
- 4.62
- Disclosed:
- Aug 10, 2022
SP Project & Document Manager [sp-client-document-manager] < 4.58 (closed)
unknown
[en] The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
- Affected:
- up to 4.58
- Fixed in:
- 4.58
- Disclosed:
- Jul 25, 2022
CVE-2022-1551 on NVD →
SP Project & Document Manager <= 4.57 - Sensitive File Disclosure
medium
The SP Project & Document Manager WordPress plugin through 4.57 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
- CVSS:
- 5.3
- Affected:
- up to 4.57
- Fixed in:
- 4.58
- Disclosed:
- Jun 28, 2022
CVE-2022-1551 on NVD →
SP Project & Document Manager <= 4.56 - Cross-Site Request Forgery and Cross-Site Scripting
critical
The SP Project & Document Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.56. This is due to missing or incorrect nonce validation in several functions. Furthermore, in several instances user input is not properly sanitized or escaped. This makes it possible...
- CVSS:
- 9.6
- Affected:
- up to 4.56
- Fixed in:
- 4.57
- Disclosed:
- Jun 17, 2022
SP Project & Document Manager [sp-client-document-manager] < 4.57 (closed)
unknown
The SP Project & Document Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.56. This is due to missing or incorrect nonce validation in several functions. Furthermore, in several instances user input is not properly sanitized or escaped. This makes it possible...
- Affected:
- up to 4.57
- Fixed in:
- 4.57
- Disclosed:
- Jun 17, 2022
SP Project & Document Manager [sp-client-document-manager] < 4.24 (closed)
unknown
[en] The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows...
- Affected:
- up to 4.24
- Fixed in:
- 4.24
- Disclosed:
- Apr 25, 2022
CVE-2021-4225 on NVD →
SP Project & Document Manager <= 4.25 - Reflected Cross-Site Scripting
medium
The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via the from and to parameters in the ~/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.25.
- CVSS:
- 6.1
- Affected:
- up to 4.25
- Fixed in:
- 4.26
- Disclosed:
- Aug 16, 2021
CVE-2021-38315 on NVD →
SP Project & Document Manager [sp-client-document-manager] < 4.33 (closed)
unknown
[en] The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via the from and to parameters in the ~/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.25.
- Affected:
- up to 4.33
- Fixed in:
- 4.33
- Disclosed:
- Aug 16, 2021
CVE-2021-38315 on NVD →
SP Project & Document Manager <= 4.23 - Subscriber+ Arbitrary File Upload
high
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows serve...
- CVSS:
- 8.8
- Affected:
- up to 4.24
- Fixed in:
- 4.24
- Disclosed:
- Jul 28, 2021
CVE-2021-4225 on NVD →
SP Project & Document Manager [sp-client-document-manager] < 4.22 (closed)
unknown
[en] The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by chang...
- Affected:
- up to 4.22
- Fixed in:
- 4.22
- Disclosed:
- Jun 14, 2021
CVE-2021-24347 on NVD →
SP Project & Document Manager <= 4.21 - Authenticated Shell Upload
high
The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing t...
- CVSS:
- 8.8
- Affected:
- up to 4.22
- Fixed in:
- 4.22
- Disclosed:
- May 25, 2021
CVE-2021-24347 on NVD →
SP Projects & Document Manager <= 2.5.9.5 - SQL Injection
critical
The SP Projects & Document Manager plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2.5.9.5 due to insufficient escaping on several user-supplied parameters and lack of sufficient preparation on existing SQL queries. This makes it possible for attackers to append additional...
- CVSS:
- 9.8
- Affected:
- up to 2.5.9.5
- Fixed in:
- 2.6.6.0
- Disclosed:
- Mar 7, 2016
SP Projects & Document Manager <= 2.6.0.0 - Arbitrary File Upload
critical
The SP Projects & Document Manager plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.6.0.0 due to insufficient file type validation on the cdm_upload_file() function. This makes it possible for attackers to upload arbitrary files on the affected site's server which may mak...
- CVSS:
- 9.8
- Affected:
- up to 2.6.1.3
- Fixed in:
- 2.6.1.4
- Disclosed:
- Mar 7, 2016
SP Projects & Document Manager <= 2.5.9.5 - Cross-Site Scripting
medium
The SP Projects & Document Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.9.5 due to insufficient input sanitization and output escaping on several parameters. This makes it possible for attackers to inject arbitrary web scripts that may execute in a victim's br...
- CVSS:
- 6.1
- Affected:
- up to 2.6.0.0
- Fixed in:
- 2.6.1.4
- Disclosed:
- Mar 7, 2016
SP Project & Document Manager [sp-client-document-manager] < 2.6.1.4 (closed)
unknown
The SP Projects & Document Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.9.5 due to insufficient input sanitization and output escaping on several parameters. This makes it possible for attackers to inject arbitrary web scripts that may execute in a victim's br...
- Affected:
- up to 2.6.1.4
- Fixed in:
- 2.6.1.4
- Disclosed:
- Mar 7, 2016
SP Project & Document Manager [sp-client-document-manager] < 2.6.6.0 (closed)
unknown
The SP Projects & Document Manager plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2.5.9.5 due to insufficient escaping on several user-supplied parameters and lack of sufficient preparation on existing SQL queries. This makes it possible for attackers to append additional...
- Affected:
- up to 2.6.6.0
- Fixed in:
- 2.6.6.0
- Disclosed:
- Mar 7, 2016
SP Project & Document Manager [sp-client-document-manager] < 2.6.1.4 (closed)
unknown
The SP Projects & Document Manager plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.6.0.0 due to insufficient file type validation on the cdm_upload_file() function. This makes it possible for attackers to upload arbitrary files on the affected site's server which may mak...
- Affected:
- up to 2.6.1.4
- Fixed in:
- 2.6.1.4
- Disclosed:
- Mar 7, 2016
SP Project & Document Manager [sp-client-document-manager] < 2.6.0.0 (closed)
unknown
This plugin is prone to an arbitrary file upload, code execution, SQL injection and XSS vulnerabilities.
Update the plugin.
- Affected:
- up to 2.6.0.0
- Fixed in:
- 2.6.0.0
- Disclosed:
- Mar 7, 2016
SP Project & Document Manager <= 2.5.9.5 - Cross-Site Request Forgery
high
The SP Project & Document Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.9.5. This is due to missing nonce validation on various functions. This makes it possible for unauthenticated attackers to perform several actions such as modifying plugin settings vi...
- CVSS:
- 8.8
- Affected:
- up to 2.5.9.5
- Fixed in:
- 2.6.0.0
- Disclosed:
- Feb 2, 2016
SP Project & Document Manager [sp-client-document-manager] < 2.6.0.0 (closed)
unknown
The SP Project & Document Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.9.5. This is due to missing nonce validation on various functions. This makes it possible for unauthenticated attackers to perform several actions such as modifying plugin settings vi...
- Affected:
- up to 2.6.0.0
- Fixed in:
- 2.6.0.0
- Disclosed:
- Feb 2, 2016
SP Project & Document Manager [sp-client-document-manager] < 2.5.4 (closed)
unknown
SP Project & Document Manager plugin is prone to a blind SQL injection that is in the thumbnails() function (location: /wp-content/plugins/sp-client-document-manager/ajax.php).
Upgrade the plugin.
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
- Disclosed:
- Mar 31, 2015
SP Project & Document Manager [sp-client-document-manager] < 2.4.4 (closed)
unknown
[en] Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manager) 2.4.1 and earlier for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) vendor_email[] parameter in the email_vendor function or id p...
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.4
- Disclosed:
- Dec 2, 2014
CVE-2014-9178 on NVD →
SP Project & Document Manager < 2.4.4 - Multiple SQL Injection
critical
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manager) 2.4.1 and earlier for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) vendor_email[] parameter in the email_vendor function or id parame...
- CVSS:
- 9.8
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.4
- Disclosed:
- Nov 20, 2014
CVE-2014-9178 on NVD →
SP Project & Document Manager [sp-client-document-manager] < 2.6.0.0 (closed)
unknown
The SP Project & Document Manager WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.
- Affected:
- up to 2.6.0.0
- Fixed in:
- 2.6.0.0
SP Project & Document Manager [sp-client-document-manager] < 2.5.4 (closed)
unknown
The SP Project & Document Manager WordPress plugin was affected by a Blind SQL Injection security vulnerability.
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
SP Project & Document Manager [sp-client-document-manager] < 2.5.4 (closed)
unknown
The SP Project & Document Manager WordPress plugin was affected by a Blind SQL Injection security vulnerability.
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
SP Project & Document Manager [sp-client-document-manager] <= 4.70 (unfixed + closed)
unknown
- Affected:
- up to 4.70
- Fix:
- No patched version reported
CVE-2024-31118 on NVD →