Pluck
by Pluck
Source repositories
CVEs (47)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-27083 | 0.00 | — | 0.01 | Jun 22, 2023 | An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality. | |||
| CVE-2020-20919 | 0.00 | — | 0.01 | Jun 20, 2023 | File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file. | |||
| CVE-2020-20918 | 0.00 | — | 0.01 | Jun 20, 2023 | An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page. | |||
| CVE-2023-25828 | 0.00 | — | 0.02 | Mar 27, 2023 | Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which… | |||
| CVE-2022-26589 | 0.00 | — | 0.00 | Apr 12, 2022 | A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages. | |||
| CVE-2022-27432 | 0.00 | — | 0.01 | Mar 29, 2022 | A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover. | |||
| CVE-2021-27984 | 0.00 | — | 0.03 | Dec 10, 2021 | In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files. | |||
| CVE-2021-31747 | 0.00 | — | 0.00 | Dec 10, 2021 | Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks. | |||
| CVE-2021-31746 | 0.00 | — | 0.02 | Dec 10, 2021 | Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution. | |||
| CVE-2021-31745 | 0.00 | — | 0.01 | Dec 10, 2021 | Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular… | |||
| CVE-2020-24740 | 0.00 | — | 0.00 | May 18, 2021 | An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage | |||
| CVE-2020-18198 | 0.00 | — | 0.01 | May 17, 2021 | Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component " /admin.php?action=images." | |||
| CVE-2020-18195 | 0.00 | — | 0.01 | May 17, 2021 | Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page." | |||
| CVE-2020-21564 | 0.00 | — | 0.03 | Sep 30, 2020 | An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files. | |||
| CVE-2019-11344 | 0.00 | — | 0.04 | Apr 19, 2019 | data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked. | |||
| CVE-2019-9051 | 0.00 | — | 0.01 | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI. | |||
| CVE-2019-9048 | 0.00 | — | 0.01 | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI. | |||
| CVE-2019-9050 | 0.00 | — | 0.02 | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive, which is then extracted and executed. | |||
| CVE-2019-9049 | 0.00 | — | 0.01 | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI. | |||
| CVE-2019-9052 | 0.00 | — | 0.01 | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI. |
- CVE-2023-27083Jun 22, 2023risk 0.00cvss —epss 0.01
An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.
- CVE-2020-20919Jun 20, 2023risk 0.00cvss —epss 0.01
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
- CVE-2020-20918Jun 20, 2023risk 0.00cvss —epss 0.01
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
- CVE-2023-25828Mar 27, 2023risk 0.00cvss —epss 0.02
Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which…
- CVE-2022-26589Apr 12, 2022risk 0.00cvss —epss 0.00
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.
- CVE-2022-27432Mar 29, 2022risk 0.00cvss —epss 0.01
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
- CVE-2021-27984Dec 10, 2021risk 0.00cvss —epss 0.03
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
- CVE-2021-31747Dec 10, 2021risk 0.00cvss —epss 0.00
Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.
- CVE-2021-31746Dec 10, 2021risk 0.00cvss —epss 0.02
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.
- CVE-2021-31745Dec 10, 2021risk 0.00cvss —epss 0.01
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular…
- CVE-2020-24740May 18, 2021risk 0.00cvss —epss 0.00
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
- CVE-2020-18198May 17, 2021risk 0.00cvss —epss 0.01
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component " /admin.php?action=images."
- CVE-2020-18195May 17, 2021risk 0.00cvss —epss 0.01
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page."
- CVE-2020-21564Sep 30, 2020risk 0.00cvss —epss 0.03
An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.
- CVE-2019-11344Apr 19, 2019risk 0.00cvss —epss 0.04
data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.
- CVE-2019-9051Feb 23, 2019risk 0.00cvss —epss 0.01
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI.
- CVE-2019-9048Feb 23, 2019risk 0.00cvss —epss 0.01
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI.
- CVE-2019-9050Feb 23, 2019risk 0.00cvss —epss 0.02
An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive, which is then extracted and executed.
- CVE-2019-9049Feb 23, 2019risk 0.00cvss —epss 0.01
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.
- CVE-2019-9052Feb 23, 2019risk 0.00cvss —epss 0.01
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI.
Page 2 of 3