📦 Soplanning

by Soplanning

🔍 What is Soplanning?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-9574

CRITICAL CVSS 9.8 Oct 7, 2024

This SQL injection vulnerability in SOPlanning versions before 1.45 allows remote attackers to execute arbitrary SQL queries through the 'by' parameter in the user_groupes.php endpoint. Attackers can ...

CVE-2024-27114

CRITICAL CVSS 9.8 Sep 11, 2024

CVE-2024-27114 is an unauthenticated remote code execution vulnerability in SO Planning online planning tool. Attackers can upload PHP files that execute for milliseconds before deletion when public v...

CVE-2024-27112

CRITICAL CVSS 9.8 Sep 11, 2024

An unauthenticated SQL injection vulnerability exists in SO Planning tool when public view is enabled, allowing attackers to execute arbitrary SQL commands on the database. This affects all organizati...

CVE-2025-62730

HIGH CVSS 8.8 Nov 20, 2025

SOPlanning users with the user_manage_team role can assign administrative permissions to any user, including themselves, allowing privilege escalation to admin. This affects both Bulk Update and regul...

CVE-2025-62294

HIGH CVSS 7.5 Nov 20, 2025

SOPlanning's password recovery token generation uses predictable values, allowing attackers to brute-force tokens and hijack any user account. This affects all SOPlanning installations before version ...

CVE-2025-62731

MEDIUM CVSS 4.8 Nov 20, 2025

SOPlanning's public holidays feature contains a stored cross-site scripting vulnerability that allows attackers with access to the feature to inject malicious HTML/JavaScript. When users view affected...

CVE-2025-62293

MEDIUM CVSS 5.4 Nov 20, 2025

SOPlanning versions before 1.55 have a broken access control vulnerability in the /status endpoint that allows authenticated attackers to manipulate project statuses without proper authorization. This...

CVE-2025-62295

MEDIUM CVSS 5.4 Nov 20, 2025

SOPlanning versions before 1.55 contain a stored cross-site scripting (XSS) vulnerability in the /groupe_form endpoint. Attackers with medium privileges can inject malicious HTML and JavaScript that e...

CVE-2025-62296

MEDIUM CVSS 5.4 Nov 20, 2025

SOPlanning versions before 1.55 contain a stored cross-site scripting (XSS) vulnerability in the /taches endpoint. Attackers with medium privileges can inject malicious HTML and JavaScript that execut...

CVE-2025-62297

MEDIUM CVSS 5.4 Nov 20, 2025

SOPlanning web application is vulnerable to stored cross-site scripting (XSS) in the /projets endpoint. An attacker with medium privileges can inject malicious HTML and JavaScript that executes when o...

CVE-2025-62729

MEDIUM CVSS 5.4 Nov 20, 2025

SOPlanning web application is vulnerable to stored cross-site scripting (XSS) in the /status endpoint. An authenticated attacker can inject malicious HTML and JavaScript that executes when other users...

CVE-2024-57170

MEDIUM CVSS 6.5 Mar 18, 2025

SOPlanning 1.53.00 has a directory traversal vulnerability in the upload.php file that allows authenticated attackers to delete arbitrary files by manipulating the 'fichier_to_delete' parameter with p...

CVE-2024-9573

MEDIUM CVSS 6.3 Oct 7, 2024

This SQL injection vulnerability in SOPlanning versions before 1.45 allows remote attackers to execute arbitrary SQL queries through the 'by' parameter in groupe_list.php. This could enable extraction...

CVE-2024-9571

MEDIUM CVSS 6.3 Oct 7, 2024

A Cross-Site Scripting (XSS) vulnerability in SOPlanning versions before 1.45 allows remote attackers to inject malicious scripts via the /soplanning/www/process/xajax_server.php endpoint. This could ...