Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

SP Project & Document Manager — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in SP Project & Document Manager, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the SP Project & Document Manager product, a document management solution, focusing on specific weakness types and associated security tags. It collects historical records of reported flaws, covering advisories published over the last five years, including patches and severity classifications. Readers can track this vendor's advisory history, analyze the prevalence of particular weakness classes such as authentication bypass or injection flaws, and review the vulnerability history specific to this document manager application.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-10737 SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function CWE-862 7.5 High 2026-06-04
CVE-2024-31118 WordPress SP Project & Document Manager plugin <= 4.70 - Broken Access Control to XSS vulnerability CWE-862 6.5 Medium 2026-02-17
CVE-2024-37224 WordPress SP Project & Document Manager plugin <= 4.71 - Directory Traversal vulnerability CWE-22 7.5 High 2024-07-09
CVE-2024-3749 SP Project & Document Manager <= 4.71 - Subscriber+ File Download via IDOR 6.5AI Medium AI 2024-05-15
CVE-2024-3748 SP Project & Document Manager <= 4.71 - Data Update via IDOR 4.3AI Medium AI 2024-05-15
CVE-2024-1693 SP Project & Document Manager <= 4.70 - Authenticated (Subscriber+) Arbitrary Folder Name Update CWE-639 4.3 Medium 2024-05-09
CVE-2024-33923 WordPress SP Project & Document Manager plugin <= 4.69 - Broken Access Control vulnerability CWE-862 6.3 Medium 2024-05-03
CVE-2024-32551 WordPress SP Project & Document Manage plugin <= 4.71 - Auth. SQL Injection vulnerability CWE-89 7.6 High 2024-04-18
CVE-2024-24868 WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL Injection CWE-89 8.5 High 2024-02-28
CVE-2023-36677 WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to SQL Injection CWE-89 8.3 High 2023-11-03
CVE-2023-36530 WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium 2023-08-10
CVE-2023-3063 SP Project & Document Manager <= 4.67 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change CWE-639 8.8 High 2023-06-30
CVE-2022-1551 SP Project & Document Manager < 4.58 - Sensitive File Disclosure 6.5 - 2022-07-25
CVE-2021-4225 SP Project & Document Manager < 4.24 - Subscriber+ Shell Upload CWE-434 8.8 - 2022-04-25
CVE-2021-38315 SP Project & Document Manager <= 4.25 Reflected Cross-Site Scripting CWE-79 6.1 Medium 2021-08-16
CVE-2021-24347 SP Project & Document Manager <2 4.22 - Authenticated Shell Upload CWE-178 8.8 - 2021-06-14

All 16 known CVE vulnerabilities affecting SP Project & Document Manager with full Chinese analysis, references, and POCs where available.