VYPR

Plenti

by Plenti

Source repositories

CVEs (3)

  • CVE-2025-26260HigMar 12, 2025
    risk 0.50cvss 8.8epss 0.01

    Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.

  • CVE-2024-49381HigOct 25, 2024
    risk 0.42cvss 7.5epss 0.01

    Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write deletion when a plenti user serves their website. This issue may lead to information loss. Version 0.7.2…

  • CVE-2024-49380HigOct 25, 2024
    risk 0.42cvss 7.5epss 0.03

    Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote Code Execution. Version…