Soplanning is a project and resource management application that, despite a narrow product footprint, has accumulated a substantial disclosure volume and ranks among the more prominent vendors in the landscape. Vulnerabilities affecting the product skew toward critical-severity outcomes and frequently acquire public exploit code, reflecting the application's exposure as a web-facing management platform and the severity of its recurring weakness classes. The exposure concentrates in the core Soplanning product and recurs through application-layer input-handling flaws including cross-site scripting, SQL injection, cross-site request forgery, path traversal, and information exposure, which are characteristic of web applications handling business-critical project data and user authentication. Defenders should treat this vendor's advisories as high-priority for any deployed instances and prioritize patching of internet-reachable deployments, since the weakness classes here afford both direct exploitation and lateral movement within the application's privilege model. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Soplanning over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8676MEDIUM Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (d | Aug 31, 2017 | 5.3 | 52 | NO | YES |
CVE-2024-27115CRITICAL A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that | Sep 11, 2024 | 9.8 | 40 | NO | YES |
CVE-2014-8673CRITICAL Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33. | Jan 7, 2020 | 9.8 | 40 | NO | YES |
CVE-2026-50644HIGH SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form | Jul 9, 2026 | 8.6 | 35 | NO | NO |
CVE-2014-8675HIGH Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain a calendar owner's password v | Aug 31, 2017 | 7.5 | 34 | NO | YES |
CVE-2026-40546HIGH SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inject arbitrary SQL commands, potentially gaining full control | Jun 1, 2026 | 8.7 | 33 | NO | NO |
CVE-2026-40543HIGH SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives containin | Jun 1, 2026 | 8.8 | 33 | NO | NO |
CVE-2024-57169CRITICAL A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to bypass upload restrictions and p | Mar 18, 2025 | 9.8 | 29 | NO | NO |
CVE-2020-13963CRITICAL SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in t | Mar 21, 2021 | 9.8 | 29 | NO | NO |
CVE-2014-8674MEDIUM Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET par | Jan 6, 2020 | 5.4 | 29 | NO | YES |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Soplanning.
Media articles that mention a CVE ID that affects a product developed by Soplanning — matched by CVE ID, not by vendor name.