Pluck
by Pluck
Source repositories
CVEs (53)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-27083 | Hig | 0.47 | 7.2 | 0.01 | Jun 22, 2023 | An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality. | ||
| CVE-2020-20919 | Hig | 0.47 | 7.2 | 0.01 | Jun 20, 2023 | File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file. | ||
| CVE-2020-20918 | Hig | 0.47 | 7.2 | 0.01 | Jun 20, 2023 | An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page. | ||
| CVE-2023-25828 | Hig | 0.47 | 7.2 | 0.02 | Mar 27, 2023 | Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which… | ||
| CVE-2019-9050 | Hig | 0.47 | 7.2 | 0.02 | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive, which is then extracted and executed. | ||
| CVE-2022-26589 | Med | 0.42 | 6.5 | 0.00 | Apr 13, 2022 | A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages. | ||
| CVE-2019-9052 | Med | 0.42 | 6.5 | 0.01 | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI. | ||
| CVE-2019-9051 | Med | 0.42 | 6.5 | 0.01 | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI. | ||
| CVE-2019-9049 | Med | 0.42 | 6.5 | 0.01 | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI. | ||
| CVE-2019-9048 | Med | 0.42 | 6.5 | 0.01 | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI. | ||
| CVE-2018-7197 | Med | 0.40 | 6.1 | 0.02 | Feb 18, 2018 | An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL. | ||
| CVE-2026-31205 | Med | 0.37 | 5.7 | 0.00 | May 4, 2026 | Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanitizePageContent function | ||
| CVE-2018-16633 | Med | 0.35 | 5.4 | 0.01 | Dec 4, 2018 | Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title. | ||
| CVE-2018-16729 | Med | 0.35 | 5.4 | 0.01 | Sep 12, 2018 | Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files. | ||
| CVE-2014-8707 | Med | 0.35 | 5.4 | 0.01 | Mar 17, 2017 | Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbitrary web script or HTML via the "edit HTML source" option. | ||
| CVE-2014-8706 | Med | 0.35 | 5.3 | 0.01 | Mar 17, 2017 | Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to an array; or (4) changing the image parameter to a string, which reveals the… | ||
| CVE-2024-9405 | Med | 0.34 | 5.3 | 0.00 | Oct 1, 2024 | An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or… | ||
| CVE-2023-27082 | Med | 0.31 | 4.8 | 0.01 | Jun 26, 2023 | Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file. | ||
| CVE-2021-31747 | Med | 0.31 | 4.8 | 0.00 | Dec 10, 2021 | Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks. | ||
| CVE-2020-24740 | Med | 0.28 | 4.3 | 0.00 | May 18, 2021 | An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage |
- risk 0.47cvss 7.2epss 0.01
An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.
- risk 0.47cvss 7.2epss 0.01
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
- risk 0.47cvss 7.2epss 0.01
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
- risk 0.47cvss 7.2epss 0.02
Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which…
- risk 0.47cvss 7.2epss 0.02
An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive, which is then extracted and executed.
- risk 0.42cvss 6.5epss 0.00
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL.
- risk 0.37cvss 5.7epss 0.00
Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanitizePageContent function
- risk 0.35cvss 5.4epss 0.01
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title.
- risk 0.35cvss 5.4epss 0.01
Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files.
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbitrary web script or HTML via the "edit HTML source" option.
- risk 0.35cvss 5.3epss 0.01
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to an array; or (4) changing the image parameter to a string, which reveals the…
- risk 0.34cvss 5.3epss 0.00
An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or…
- risk 0.31cvss 4.8epss 0.01
Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file.
- risk 0.31cvss 4.8epss 0.00
Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.
- risk 0.28cvss 4.3epss 0.00
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
Page 2 of 3