S4E just found a medium-severity finding from generic tokens detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2021-24347

8.8
CVSS
Description

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

Attack Vector
-
Privileges Req.
-
User Interaction
-
sp project & document manager
Updated Sep 26, 2026View on NVD →
S4E scanner

CVE history: sp project & document manager

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →