soplanning CVE Vulnerabilities & Metrics

Focus on soplanning vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About soplanning Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with soplanning. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total soplanning CVEs: 23
Earliest CVE date: 31 Aug 2017, 22:29 UTC
Latest CVE date: 07 Oct 2024, 15:15 UTC

Latest CVE reference: CVE-2024-9574

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 8

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical soplanning CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.3

Max CVSS: 9.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 13
4.0-6.9 7
7.0-8.9 2
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS soplanning CVEs

These are the five CVEs with the highest CVSS scores for soplanning, sorted by severity first and recency.

All CVEs for soplanning

CVE-2024-9574 soplanning vulnerability CVSS: 0 07 Oct 2024, 15:15 UTC

SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

CVE-2024-9573 soplanning vulnerability CVSS: 0 07 Oct 2024, 15:15 UTC

SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to send a specially crafted query and extract all the information stored on the server.

CVE-2024-9572 soplanning vulnerability CVSS: 0 07 Oct 2024, 15:15 UTC

Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/groupe_save.php, in the groupe_id parameter. This could allow a remote user to send a specially crafted query to an authenticated user and steal their session details.

CVE-2024-9571 soplanning vulnerability CVSS: 0 07 Oct 2024, 15:15 UTC

Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/xajax_server.php, affecting multiple parameters. This could allow a remote user to send a specially crafted query to an authenticated user and partially take control of their browser session.

CVE-2024-27115 soplanning vulnerability CVSS: 0 11 Sep 2024, 14:15 UTC

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the possibility of execution of code on the underlying system when the file is triggered. The vulnerability has been remediated in version 1.52.02.

CVE-2024-27114 soplanning vulnerability CVSS: 0 11 Sep 2024, 14:15 UTC

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to execution of code on the underlying system. The vulnerability has been remediated in version 1.52.02.

CVE-2024-27113 soplanning vulnerability CVSS: 0 11 Sep 2024, 14:15 UTC

An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database by exporting it as a CSV file. The vulnerability has been remediated in version 1.52.02.

CVE-2024-27112 soplanning vulnerability CVSS: 0 11 Sep 2024, 14:15 UTC

A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database. The vulnerability has been remediated in version 1.52.02.

CVE-2020-13963 soplanning vulnerability CVSS: 7.5 21 Mar 2021, 21:15 UTC

SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest account).

CVE-2020-25867 soplanning vulnerability CVSS: 4.3 07 Oct 2020, 21:15 UTC

SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.

CVE-2020-15597 soplanning vulnerability CVSS: 3.5 11 Aug 2020, 16:15 UTC

SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field.

CVE-2020-9339 soplanning vulnerability CVSS: 3.5 22 Feb 2020, 22:15 UTC

SOPlanning 1.45 allows XSS via the Name or Comment to status.php.

CVE-2020-9338 soplanning vulnerability CVSS: 3.5 22 Feb 2020, 22:15 UTC

SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.

CVE-2020-9269 soplanning vulnerability CVSS: 9.0 18 Feb 2020, 19:15 UTC

SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as demonstrated by export_ical.php.

CVE-2020-9268 soplanning vulnerability CVSS: 5.0 18 Feb 2020, 19:15 UTC

SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.

CVE-2020-9267 soplanning vulnerability CVSS: 4.3 18 Feb 2020, 19:15 UTC

SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.

CVE-2020-9266 soplanning vulnerability CVSS: 4.3 18 Feb 2020, 19:15 UTC

SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.

CVE-2019-20179 soplanning vulnerability CVSS: 6.5 09 Jan 2020, 22:15 UTC

SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.

CVE-2014-8673 soplanning vulnerability CVSS: 7.5 07 Jan 2020, 18:15 UTC

Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.

CVE-2014-8674 soplanning vulnerability CVSS: 3.5 06 Jan 2020, 22:15 UTC

Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary code.

CVE-2014-8677 soplanning vulnerability CVSS: 3.5 31 Aug 2017, 22:29 UTC

The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration database is down, and smarty/templates_c is not writable to execute arbitrary php code via a crafted database name.

CVE-2014-8676 soplanning vulnerability CVSS: 5.0 31 Aug 2017, 22:29 UTC

Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.

CVE-2014-8675 soplanning vulnerability CVSS: 5.0 31 Aug 2017, 22:29 UTC

Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain a calendar owner's password via a brute-force attack on the embedded password hash.