Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
pluck-cms pluck vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-27082
Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 up to and including 4.7.16-dev4 allows remote malicious users to run arbitrary code via upload of crafted html file.
Pluck-cms Pluck 4.7.16
Pluck-cms Pluck
NA
CVE-2023-27083
An issue discovered in /admin.php in Pluck CMS 4.7.15 up to and including 4.7.16-dev5 allows remote malicious users to run arbitrary code via manage file functionality.
Pluck-cms Pluck 4.7.16
Pluck-cms Pluck
NA
CVE-2023-25828
Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which...
Pluck-cms Pluck 4.7.16
Pluck-cms Pluck
1 Github repository
7.5
CVSSv2
CVE-2018-11736
An issue exists in Pluck prior to 4.7.7-dev2. /data/inc/images.php allows remote malicious users to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.
Pluck-cms Pluck
Pluck-cms Pluck 4.7.7
6.5
CVSSv2
CVE-2020-21564
An issue exists in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.
Pluck-cms Pluck 4.7.10
Pluck-cms Pluck 4.7.11
6.5
CVSSv2
CVE-2020-29607
A file upload restriction bypass vulnerability in Pluck CMS prior to 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
Pluck-cms Pluck
3 Github repositories
7.5
CVSSv2
CVE-2018-11331
An issue exists in Pluck prior to 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.
Pluck-cms Pluck
3.5
CVSSv2
CVE-2018-11330
An issue exists in Pluck prior to 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted.
Pluck-cms Pluck
4.3
CVSSv2
CVE-2018-7197
An issue exists in Pluck up to and including 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL.
Pluck-cms Pluck
1 Github repository
3.5
CVSSv2
CVE-2018-16729
Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files.
Pluck-cms Pluck 4.7.7
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »