Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
pluxml vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2012-2227
Directory traversal vulnerability in update/index.php in PluXml prior to 5.1.6 allows remote malicious users to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the default_lang parameter.
Pluxml Pluxml
1 EDB exploit
5
CVSSv2
CVE-2012-4674
PluXml prior to 5.1.6 allows remote malicious users to obtain the installation path via the PHPSESSID.
Pluxml Pluxml
4.3
CVSSv2
CVE-2012-4675
Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors related to file update.
Pluxml Pluxml
3.5
CVSSv2
CVE-2022-24585
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload in the author parameter.
Pluxml Pluxml 5.8.7
3.5
CVSSv2
CVE-2022-24586
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload in the content and thumbnail parameters.
Pluxml Pluxml 5.8.7
3.5
CVSSv2
CVE-2022-24587
A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows malicious users to execute arbitrary web scripts or HTML.
Pluxml Pluxml 5.8.7
3.5
CVSSv2
CVE-2021-38602
PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.
Pluxml Pluxml 5.8.7
1 Github repository
3.5
CVSSv2
CVE-2021-38603
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.
Pluxml Pluxml 5.8.7
1 Github repository
3.5
CVSSv2
CVE-2017-1001001
PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges.
Pluxml Pluxml 5.6
7.5
CVSSv2
CVE-2020-18185
class.plx.admin.php in PluXml 5.7 allows malicious users to execute arbitrary PHP code by modify the configuration file in a linux environment.
Pluxml Pluxml 5.7
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3012
CVE-2024-30200
XXE
CVE-2023-24955
CVE-2023-42931
CVE-2024-29231
remote code execution
cross-site scripting
CVE-2024-0677
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »