Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Smartypantsplugins

First CVE: May 10, 2013Active for: 13 yearsTotal CVEs: 15
44.5
VTI Score
High

Smartypantsplugins develops a focused line of WordPress and SharePoint plugins for project management, document handling, and specialized domains such as funeral services. The vendor's vulnerability profile centers on web-application input handling and access control, with recurring issues in cross-site scripting, SQL injection, and authorization bypass—weaknesses typical of server-side plugins that process user input and manage role-based permissions. Public exploit code has an elevated tendency to emerge for this vendor's flaws; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Smartypantsplugins over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 10, 2013
13 years ago
Most Recent CVE
Jul 9, 2024
745 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24347HIGH
The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be execu
Jun 14, 20218.875NOYES
CVE-2014-9178HIGH
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manager) 2.4.1 and earlier for WordP
Dec 2, 20147.530NOYES
CVE-2021-4225HIGH
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other si
Apr 25, 20228.828NONO
CVE-2023-3063HIGH
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providin
Jun 30, 20238.825NONO
CVE-2023-36677HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affe
Nov 3, 20238.824NONO
CVE-2021-38324HIGH
The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve informati
Sep 9, 20217.524NONO
CVE-2024-24868HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Docu
Feb 28, 20248.823NONO
CVE-2013-3529MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote attackers to inject arbitrary web script
May 10, 20134.322NOYES
CVE-2024-3749MEDIUM
The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user
May 15, 20246.521NONO
CVE-2022-34857MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress
Aug 22, 20226.121NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
53%
47%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network13 (86.7%)
Unknown2 (13.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (86.7%)
High0 (0.0%)
Unknown2 (13.3%)
User Interaction
None10 (66.7%)
Unknown2 (13.3%)
Required3 (20.0%)
Privileges Required
Low8 (53.3%)
High1 (6.7%)
None4 (26.7%)
Unknown2 (13.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.7% of CVEs· 98th percentile
Nuclei
1 CVE
6.7% of CVEs· 96th percentile
ExploitDB
2 CVEs
13.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Smartypantsplugins.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Smartypantsplugins — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Smartypantsplugins's Products

View all 4 CNAs →

Top CWEs