Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
pluck vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2020-20951
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
Pluck-cms Pluck 4.7.10
7.2
CVSSv3
CVE-2020-20969
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote malicious user to execute arbitrary code via the trashcan_restoreitem.php file.
Pluck-cms Pluck 4.7.10
5.4
CVSSv3
CVE-2014-8707
Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbitrary web script or HTML via the "edit HTML source" option.
Pluck-cms Pluck 4.7.2
9.8
CVSSv3
CVE-2014-8708
Pluck CMS 4.7.2 allows remote malicious users to execute arbitrary code via the blog form feature.
Pluck-cms Pluck 4.7.2
8.8
CVSSv3
CVE-2023-50564
An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows malicious users to execute arbitrary code via uploading a crafted ZIP file.
Pluck-cms Pluck 4.7.18
9.8
CVSSv3
CVE-2019-11344
data/inc/files.php in Pluck 4.7.8 allows remote malicious users to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.
Pluck-cms Pluck 4.7.8
NA
CVE-2008-6842
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the post parameter.
Pluck-cms Pluck 4.6.1
1 EDB exploit
NA
CVE-2012-1227
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in pluck 4.7 allow remote malicious users to hijack the authentication of admins for requests that (1) modify the admin email address or (2) modify the blog title via a settings action; (3) add a page via an ...
Pluck-cms Pluck 4.7
8.8
CVSSv3
CVE-2020-18198
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote malicious users to execute arbitrary code and delete specific images via the component " /admin.php?action=images."
Pluck-cms Pluck 4.7.9
6.5
CVSSv3
CVE-2019-9049
An issue exists in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.
Pluck-cms Pluck 4.7.9
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »