CVE-2024-57169: Soplanning

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to bypass upload restrictions and potentially achieve remote code execution by uploading malicious files.

Affected products

Published 2025-03-18. Last modified 2026-06-17.