VYPR

Pluck

by Pluck

Source repositories

CVEs (47)

  • CVE-2023-27083Jun 22, 2023
    risk 0.00cvss epss 0.01

    An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.

  • CVE-2020-20919Jun 20, 2023
    risk 0.00cvss epss 0.01

    File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.

  • CVE-2020-20918Jun 20, 2023
    risk 0.00cvss epss 0.01

    An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.

  • CVE-2023-25828Mar 27, 2023
    risk 0.00cvss epss 0.02

    Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which…

  • CVE-2022-26589Apr 12, 2022
    risk 0.00cvss epss 0.00

    A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.

  • CVE-2022-27432Mar 29, 2022
    risk 0.00cvss epss 0.01

    A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.

  • CVE-2021-27984Dec 10, 2021
    risk 0.00cvss epss 0.03

    In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.

  • CVE-2021-31747Dec 10, 2021
    risk 0.00cvss epss 0.00

    Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.

  • CVE-2021-31746Dec 10, 2021
    risk 0.00cvss epss 0.02

    Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.

  • CVE-2021-31745Dec 10, 2021
    risk 0.00cvss epss 0.01

    Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular…

  • CVE-2020-24740May 18, 2021
    risk 0.00cvss epss 0.00

    An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage

  • CVE-2020-18198May 17, 2021
    risk 0.00cvss epss 0.01

    Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component " /admin.php?action=images."

  • CVE-2020-18195May 17, 2021
    risk 0.00cvss epss 0.01

    Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page."

  • CVE-2020-21564Sep 30, 2020
    risk 0.00cvss epss 0.03

    An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.

  • CVE-2019-11344Apr 19, 2019
    risk 0.00cvss epss 0.04

    data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.

  • CVE-2019-9051Feb 23, 2019
    risk 0.00cvss epss 0.01

    An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI.

  • CVE-2019-9048Feb 23, 2019
    risk 0.00cvss epss 0.01

    An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI.

  • CVE-2019-9050Feb 23, 2019
    risk 0.00cvss epss 0.02

    An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive, which is then extracted and executed.

  • CVE-2019-9049Feb 23, 2019
    risk 0.00cvss epss 0.01

    An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.

  • CVE-2019-9052Feb 23, 2019
    risk 0.00cvss epss 0.01

    An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI.