← WordPress Vulnerabilities
WordPress security by component

School Management System for

School Management System for is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Mar 07, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: school-management-system

CVE-2024-9658: School Management System for: Filesystem traversal

School Management System for is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.

PublishedMar 07, 2025
Safe version guidanceSee mitigation notes
Safe version
Mar 07, 2025 CVE-2024-9658
School Management System for: Filesystem traversal
School Management System for is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVDPending
Mar 07, 2025 CVE-2024-12611
School Management System for: Cross-site scripting
School Management System for is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.3
NVDPending
Mar 07, 2025 CVE-2024-12610
School Management System for: A security weakness
School Management System for is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Mar 07, 2025 CVE-2024-12609
School Management System for: SQL injection
School Management System for is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVDPending
Mar 07, 2025 CVE-2024-12607
School Management System for: SQL injection
School Management System for is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVDPending
Nov 23, 2024 CVE-2024-9660
School Management System for: Dangerous file upload
School Management System for is affected by dangerous file upload. Exploitation requires an authenticated WordPress account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.8
NVDPending
Nov 23, 2024 CVE-2024-9659
School Management System for: Dangerous file upload
School Management System for is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.8
NVDPending
Nov 06, 2023 CVE-2022-47430
The School Management – Education & Learning Management: SQL injection
The School Management – Education & Learning Management is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.7
NVD9.8
Sep 28, 2017 CVE-2017-14843
School Management System: SQL injection
School Management System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8