Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
pluck-cms vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2023-50564
An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows malicious users to execute arbitrary code via uploading a crafted ZIP file.
Pluck-cms Pluck 4.7.18
5.4
CVSSv3
CVE-2023-5013
A vulnerability has been found in Pluck CMS 4.7.18 and classified as problematic. This vulnerability affects unknown code of the file install.php of the component Installation Handler. The manipulation of the argument contents with the input <script>alert('xss')&l...
Pluck-cms Pluck 4.7.18
4.8
CVSSv3
CVE-2023-27082
Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 up to and including 4.7.16-dev4 allows remote malicious users to run arbitrary code via upload of crafted html file.
Pluck-cms Pluck 4.7.16
Pluck-cms Pluck
7.2
CVSSv3
CVE-2023-27083
An issue discovered in /admin.php in Pluck CMS 4.7.15 up to and including 4.7.16-dev5 allows remote malicious users to run arbitrary code via manage file functionality.
Pluck-cms Pluck 4.7.16
Pluck-cms Pluck
9.8
CVSSv3
CVE-2020-20718
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote malicious user to execute arbitrary code via a crafted image file to the the save_file() parameter.
Pluck-cms Pluckcms 4.7.10
7.2
CVSSv3
CVE-2020-20969
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote malicious user to execute arbitrary code via the trashcan_restoreitem.php file.
Pluck-cms Pluck 4.7.10
7.2
CVSSv3
CVE-2020-20918
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote malicious user to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
Pluck-cms Pluck 4.7.10
7.2
CVSSv3
CVE-2020-20919
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote malicious user to execute arbitrary code and access sensitive information via the theme.php file.
Pluck-cms Pluck 4.7.10
7.2
CVSSv3
CVE-2023-25828
Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which...
Pluck-cms Pluck 4.7.16
Pluck-cms Pluck
1 Github repository
6.5
CVSSv3
CVE-2022-26589
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows malicious users to delete arbitrary pages.
Pluck-cms Pluck 4.7.15
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »