CVE-2026-40549
- EPSS 0.18%
- Veröffentlicht 01.06.2026 09:16:17
- Zuletzt bearbeitet 01.06.2026 16:37:15
SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged GET or POST request ...
CVE-2026-40548
- EPSS 0.31%
- Veröffentlicht 01.06.2026 09:16:17
- Zuletzt bearbeitet 01.06.2026 16:37:15
SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a legitimate user.csv file alongside a malicious file, which is extracted on the server....
CVE-2026-40547
- EPSS 0.45%
- Veröffentlicht 01.06.2026 09:16:17
- Zuletzt bearbeitet 01.06.2026 16:37:15
SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow reading and executing files previously added through the backup functionality. C...
CVE-2026-40546
- EPSS 0.21%
- Veröffentlicht 01.06.2026 09:16:17
- Zuletzt bearbeitet 01.06.2026 16:37:15
SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inject arbitrary SQL commands, potentially gaining full control over the database. This issue affects SOPlanning version 1.55 and be...
CVE-2026-40545
- EPSS 0.4%
- Veröffentlicht 01.06.2026 09:16:17
- Zuletzt bearbeitet 01.06.2026 16:37:15
SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the victim’s browser. This issue affects SOPlanning ve...
CVE-2026-40544
- EPSS 0.3%
- Veröffentlicht 01.06.2026 09:16:17
- Zuletzt bearbeitet 01.06.2026 16:37:15
SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a malicious user.csv file with embedded J...
CVE-2026-40543
- EPSS 0.27%
- Veröffentlicht 01.06.2026 09:16:17
- Zuletzt bearbeitet 01.06.2026 16:37:15
SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives containing user databases with usernames and password hashes, as well as the co...
CVE-2024-33724
- EPSS 0.55%
- Veröffentlicht 08.05.2026 00:00:00
- Zuletzt bearbeitet 08.05.2026 22:16:28
SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
CVE-2024-33722
- EPSS 0.24%
- Veröffentlicht 08.05.2026 00:00:00
- Zuletzt bearbeitet 08.05.2026 18:16:32
SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
CVE-2025-62731
- EPSS 0.15%
- Veröffentlicht 20.11.2025 15:44:17
- Zuletzt bearbeitet 24.11.2025 13:53:27
SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is able to inject arbitrary HTML and JS into website, which will be rendered/executed when opening multiple pages. By default only a...