VYPR

Pluck

by Pluck

Source repositories

CVEs (53)

  • CVE-2023-27083HigJun 22, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.

  • CVE-2020-20919HigJun 20, 2023
    risk 0.47cvss 7.2epss 0.01

    File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.

  • CVE-2020-20918HigJun 20, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.

  • CVE-2023-25828HigMar 27, 2023
    risk 0.47cvss 7.2epss 0.02

    Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which…

  • CVE-2019-9050HigFeb 23, 2019
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive, which is then extracted and executed.

  • CVE-2022-26589MedApr 13, 2022
    risk 0.42cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.

  • CVE-2019-9052MedFeb 23, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI.

  • CVE-2019-9051MedFeb 23, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI.

  • CVE-2019-9049MedFeb 23, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.

  • CVE-2019-9048MedFeb 23, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI.

  • CVE-2018-7197MedFeb 18, 2018
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL.

  • CVE-2026-31205MedMay 4, 2026
    risk 0.37cvss 5.7epss 0.00

    Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanitizePageContent function

  • CVE-2018-16633MedDec 4, 2018
    risk 0.35cvss 5.4epss 0.01

    Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title.

  • CVE-2018-16729MedSep 12, 2018
    risk 0.35cvss 5.4epss 0.01

    Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files.

  • CVE-2014-8707MedMar 17, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbitrary web script or HTML via the "edit HTML source" option.

  • CVE-2014-8706MedMar 17, 2017
    risk 0.35cvss 5.3epss 0.01

    Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to an array; or (4) changing the image parameter to a string, which reveals the…

  • CVE-2024-9405MedOct 1, 2024
    risk 0.34cvss 5.3epss 0.00

    An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or…

  • CVE-2023-27082MedJun 26, 2023
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file.

  • CVE-2021-31747MedDec 10, 2021
    risk 0.31cvss 4.8epss 0.00

    Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.

  • CVE-2020-24740MedMay 18, 2021
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage