VYPR

Soplanning

by Soplanning

Source repositories

CVEs (44)

  • CVE-2026-40545MedJun 1, 2026
    risk 0.33cvss epss 0.00

    SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the victim’s browser. This issue affects SOPlanning version 1.55 and below.

  • CVE-2026-40544MedJun 1, 2026
    risk 0.33cvss epss 0.00

    SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a malicious user.csv file with embedded JavaScript. The injected code…

  • CVE-2025-62731MedNov 20, 2025
    risk 0.31cvss 4.8epss 0.00

    SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is able to inject arbitrary HTML and JS into website, which will be rendered/executed when opening multiple pages. By default only administrators and users with…

  • CVE-2026-50644HigJul 9, 2026
    risk 0.00cvss epss 0.00

    SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the…

Page 3 of 3