Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SOPlanning — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in SOPlanning, with AI-generated Chinese analysis, references, and POCs.

This page details security vulnerabilities associated with SOPlanning, a business process planning software product, focusing on common weakness types and related tags. It aggregates a comprehensive collection of security flaws identified in the software, ranging from cross-site scripting and SQL injection to permission bypasses and information disclosure issues. The data covers historical records spanning from initial release up to the most recent public disclosures, ensuring a complete timeline of known security incidents. By visiting this resource, users can efficiently track vendor advisories issued by the developer to address emerging threats, deeply understand the characteristics and impact of specific weakness classes within the context of this application, and review a product's full vulnerability history to assess long-term security posture. This structured approach allows developers and security analysts to correlate specific defects with their respective resolution statuses and timeline, facilitating better risk assessment and patch management strategies. The information is sourced from verified public advisories and database entries, providing an objective view of the software's security landscape without speculation. It serves as a centralized reference for anyone needing to audit SOPlanning for potential security gaps or to understand how past vulnerabilities have been mitigated by the vendor over time.

Vendor: SOPlanning

CVE IDTitleCVSSSeverityPublished
CVE-2026-50644 SQL Injection in SOPlanning Audit Retention Configuration CWE-89--2026-07-09
CVE-2026-40549 Cross-Site Request Forgery in SOPlanning CWE-352--2026-06-01
CVE-2026-40548 Unrestricted Upload of File with Dangerous Type in SOPlanning CWE-434--2026-06-01
CVE-2026-40547 Path Traversal in SOPlanning CWE-22--2026-06-01
CVE-2026-40546 Multiple SQL Injections in SOPlanning CWE-89--2026-06-01
CVE-2026-40545 Reflected XSS in SOPlanning CWE-79--2026-06-01
CVE-2026-40544 Stored XSS in SOPlanning CWE-79--2026-06-01
CVE-2026-40543 Missing Authorization in SOPlanning CWE-862--2026-06-01
CVE-2025-62731 Stored XSS in SOPlanning CWE-79 5.4 -2025-11-20
CVE-2025-62730 Privilege Escalation via Incorrect Authorization in SOPlanning CWE-863 8.8 -2025-11-20
CVE-2025-62729 Stored XSS in SOPlanning CWE-79 5.4 -2025-11-20
CVE-2025-62297 Stored XSS in SOPlanning CWE-79 5.4 -2025-11-20
CVE-2025-62296 Stored XSS in SOPlanning CWE-79 5.4 -2025-11-20
CVE-2025-62295 Stored XSS in SOPlanning CWE-79 5.4 -2025-11-20
CVE-2025-62294 Predictable Generation of Password Recovery Token CWE-340 9.8 -2025-11-20
CVE-2025-62293 Broken Access Control in SOPlanning CWE-862 4.3 -2025-11-20
CVE-2025-41001 Cross-Site Scripting (XSS) in SOPlanning CWE-79 5.4 -2025-11-10
CVE-2024-9574 SQL Injection vulnerability in SOPlanning CWE-89 9.8 Critical2024-10-07
CVE-2024-9573 SQL Injection vulnerability in SOPlanning CWE-89 6.3 Medium2024-10-07
CVE-2024-9572 Cross-Site Scripting vulnerability in SOPlanning CWE-79 6.3 Medium2024-10-07
CVE-2024-9571 Cross-Site Scripting vulnerability in SOPlanning CWE-79 6.3 Medium2024-10-07

All 21 known CVE vulnerabilities affecting SOPlanning with full Chinese analysis, references, and POCs where available.