Smartypantsplugins develops a focused line of WordPress and SharePoint plugins for project management, document handling, and specialized domains such as funeral services. The vendor's vulnerability profile centers on web-application input handling and access control, with recurring issues in cross-site scripting, SQL injection, and authorization bypass—weaknesses typical of server-side plugins that process user input and manage role-based permissions. Public exploit code has an elevated tendency to emerge for this vendor's flaws; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smartypantsplugins over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24347HIGH The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be execu | Jun 14, 2021 | 8.8 | 75 | NO | YES |
CVE-2014-9178HIGH Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manager) 2.4.1 and earlier for WordP | Dec 2, 2014 | 7.5 | 30 | NO | YES |
CVE-2021-4225HIGH The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other si | Apr 25, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-3063HIGH The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providin | Jun 30, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-36677HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affe | Nov 3, 2023 | 8.8 | 24 | NO | NO |
CVE-2021-38324HIGH The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve informati | Sep 9, 2021 | 7.5 | 24 | NO | NO |
CVE-2024-24868HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Docu | Feb 28, 2024 | 8.8 | 23 | NO | NO |
CVE-2013-3529MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote attackers to inject arbitrary web script | May 10, 2013 | 4.3 | 22 | NO | YES |
CVE-2024-3749MEDIUM The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user | May 15, 2024 | 6.5 | 21 | NO | NO |
CVE-2022-34857MEDIUM Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress | Aug 22, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smartypantsplugins.
Media articles that mention a CVE ID that affects a product developed by Smartypantsplugins — matched by CVE ID, not by vendor name.