Skip to content
Noroxi

pluck-cms records

46 published records for vendor pluck-cms.

All records

46 records
  • An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary

    HighCVSS 8.8Proof of conceptEPSS 29%

    pluck-cms · pluckDec 14, 2023

  • An issue was discovered in Pluck before 4.7.7-dev2.

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    pluck-cms · pluckJun 5, 2018

  • In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.

    CriticalCVSS 9.8No exploitEPSS 4%

    pluck-cms · pluckMay 18, 2021

  • data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler

    CriticalCVSS 9.8No exploitEPSS 4%

    pluck-cms · pluckApr 19, 2019

  • Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.

    CriticalCVSS 9.8No exploitEPSS 3%

    pluck-cms · pluckMar 17, 2017

  • Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal

    CriticalCVSS 9.8No exploitEPSS 2%

    pluck-cms · pluckDec 10, 2021

  • An issue was discovered in Pluck before 4.7.6.

    CriticalCVSS 9.8No exploitEPSS 2%

    pluck-cms · pluckMay 21, 2018

  • PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type.

    CriticalCVSS 9.8No exploitEPSS 2%

    pluck-cms · pluckcmsJul 16, 2019

  • In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.

    HighCVSS 7.2Proof of conceptEPSS 36%

    pluck-cms · pluckMar 18, 2022

  • File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to t

    CriticalCVSS 9.8No exploitEPSS 1%

    pluck-cms · pluckcmsJun 20, 2023

  • Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.

    CriticalCVSS 9.8No exploitEPSS 1%

    pluck-cms · pluckAug 16, 2024

  • A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through

    HighCVSS 7.2Proof of conceptEPSS 33%

    pluck-cms · pluckDec 16, 2020

  • An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11.

    HighCVSS 8.8No exploitEPSS 3%

    pluck-cms · pluckSep 30, 2020

  • Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the c

    HighCVSS 8.8No exploitEPSS 1%

    pluck-cms · pluckMay 17, 2021

  • Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via th

    HighCVSS 8.8No exploitEPSS 1%

    pluck-cms · pluckMay 17, 2021

  • A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this featur

    HighCVSS 8.8No exploitEPSS 1%

    pluck-cms · pluckMar 29, 2022

  • Pluck v4.7.7 allows CSRF via admin.php?action=settings.

    HighCVSS 8.8No exploitEPSS 1%

    pluck-cms · pluckDec 4, 2018

  • In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.

    HighCVSS 8.1No exploitEPSS 3%

    pluck-cms · pluckDec 10, 2021

  • CVE-2009-1765
    32Monitor

    Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute

    MediumCVSS 6.8Proof of conceptEPSS 15%

    pluck-cms · pluckMay 22, 2009

  • File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.

    HighCVSS 7.2Proof of conceptEPSS 6%

    pluck-cms · pluckJun 20, 2023

  • Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform.

    HighCVSS 7.5No exploitEPSS 1%

    pluck-cms · pluckDec 10, 2021

  • CVE-2019-9050
    29Monitor

    An issue was discovered in Pluck 4.7.9-dev1.

    HighCVSS 7.2No exploitEPSS 2%

    pluck-cms · pluckFeb 23, 2019

  • CVE-2008-6253
    28Monitor

    Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers t

    MediumCVSS 6.8Proof of conceptEPSS 5%

    pluck-cms · pluckFeb 24, 2009

  • CVE-2008-6842
    28Monitor

    Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute a

    MediumCVSS 6.8Proof of conceptEPSS 2%

    pluck-cms · pluckJul 2, 2009

  • Authenticate Remote Code Execution in Pluck CMS

    HighCVSS 7.2No exploitEPSS 2%

    pluck-cms · pluckMar 27, 2023