Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SOPlanning — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting SOPlanning. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SOPlanning serves as workforce management and scheduling software for organizations. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for its 13 recorded CVEs. The application's web interface has frequently contained input validation weaknesses allowing unauthorized access or code execution. While no major public security incidents have been widely documented, the consistent pattern of vulnerabilities in scheduling and time-tracking components suggests potential risks for organizations relying on the platform without proper hardening. Regular security assessments and timely patching remain critical for implementations handling sensitive employee data.

Top products by SOPlanning: SOPlanning
CVE IDTitleCVSSSeverityPublished
CVE-2026-50644 SQL Injection in SOPlanning Audit Retention Configuration — SOPlanningCWE-89--2026-07-09
CVE-2026-40549 Cross-Site Request Forgery in SOPlanning — SOPlanningCWE-352--2026-06-01
CVE-2026-40548 Unrestricted Upload of File with Dangerous Type in SOPlanning — SOPlanningCWE-434--2026-06-01
CVE-2026-40547 Path Traversal in SOPlanning — SOPlanningCWE-22--2026-06-01
CVE-2026-40546 Multiple SQL Injections in SOPlanning — SOPlanningCWE-89--2026-06-01
CVE-2026-40545 Reflected XSS in SOPlanning — SOPlanningCWE-79--2026-06-01
CVE-2026-40544 Stored XSS in SOPlanning — SOPlanningCWE-79--2026-06-01
CVE-2026-40543 Missing Authorization in SOPlanning — SOPlanningCWE-862--2026-06-01
CVE-2025-62731 Stored XSS in SOPlanning — SOPlanningCWE-79 5.4 -2025-11-20
CVE-2025-62730 Privilege Escalation via Incorrect Authorization in SOPlanning — SOPlanningCWE-863 8.8 -2025-11-20
CVE-2025-62729 Stored XSS in SOPlanning — SOPlanningCWE-79 5.4 -2025-11-20
CVE-2025-62297 Stored XSS in SOPlanning — SOPlanningCWE-79 5.4 -2025-11-20
CVE-2025-62296 Stored XSS in SOPlanning — SOPlanningCWE-79 5.4 -2025-11-20
CVE-2025-62295 Stored XSS in SOPlanning — SOPlanningCWE-79 5.4 -2025-11-20
CVE-2025-62294 Predictable Generation of Password Recovery Token — SOPlanningCWE-340 9.8 -2025-11-20
CVE-2025-62293 Broken Access Control in SOPlanning — SOPlanningCWE-862 4.3 -2025-11-20
CVE-2025-41001 Cross-Site Scripting (XSS) in SOPlanning — SOPlanningCWE-79 5.4 -2025-11-10
CVE-2024-9574 SQL Injection vulnerability in SOPlanning — SOPlanningCWE-89 9.8 Critical2024-10-07
CVE-2024-9573 SQL Injection vulnerability in SOPlanning — SOPlanningCWE-89 6.3 Medium2024-10-07
CVE-2024-9572 Cross-Site Scripting vulnerability in SOPlanning — SOPlanningCWE-79 6.3 Medium2024-10-07
CVE-2024-9571 Cross-Site Scripting vulnerability in SOPlanning — SOPlanningCWE-79 6.3 Medium2024-10-07

This page lists every published CVE security advisory associated with SOPlanning. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.