pluck-cms records
46 published records for vendor pluck-cms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 12
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type16
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-384 Session Fixation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
46 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2023-50564Proof of concept | An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary pluck-cms · pluck · CWE-434 | High8.8 | — | 29.1% | Dec 14, 2023 |
42Plan | CVE-2018-11736Proof of concept | An issue was discovered in Pluck before 4.7.7-dev2.pluck-cms · pluck · CWE-434 | Critical9.8 | — | 8.6% | Jun 5, 2018 |
40Plan | CVE-2020-20951No exploit | In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.pluck-cms · pluck · CWE-77 | Critical9.8 | — | 4.0% | May 18, 2021 |
40Plan | CVE-2019-11344No exploit | data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler pluck-cms · pluck · CWE-434 | Critical9.8 | — | 3.6% | Apr 19, 2019 |
40Plan | CVE-2014-8708No exploit | Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.pluck-cms · pluck · CWE-264 | Critical9.8 | — | 3.0% | Mar 17, 2017 |
40Plan | CVE-2021-31746No exploit | Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal pluck-cms · pluck · CWE-22 | Critical9.8 | — | 2.4% | Dec 10, 2021 |
40Plan | CVE-2018-11331No exploit | An issue was discovered in Pluck before 4.7.6.pluck-cms · pluck · CWE-434 | Critical9.8 | — | 2.2% | May 21, 2018 |
40Plan | CVE-2019-1010062No exploit | PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type.pluck-cms · pluckcms · CWE-434 | Critical9.8 | — | 1.8% | Jul 16, 2019 |
39Monitor | CVE-2022-26965Proof of concept | In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.pluck-cms · pluck · CWE-434 | High7.2 | — | 36.3% | Mar 18, 2022 |
39Monitor | CVE-2020-20718No exploit | File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to tpluck-cms · pluckcms · CWE-434 | Critical9.8 | — | 1.3% | Jun 20, 2023 |
39Monitor | CVE-2024-43042No exploit | Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.pluck-cms · pluck · CWE-307 | Critical9.8 | — | 0.6% | Aug 16, 2024 |
38Monitor | CVE-2020-29607Proof of concept | A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host throughpluck-cms · pluck · CWE-434 | High7.2 | — | 33.2% | Dec 16, 2020 |
36Monitor | CVE-2020-21564No exploit | An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11.pluck-cms · pluck · CWE-434 | High8.8 | — | 3.5% | Sep 30, 2020 |
35Monitor | CVE-2020-18198No exploit | Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the cpluck-cms · pluck · CWE-352 | High8.8 | — | 0.9% | May 17, 2021 |
35Monitor | CVE-2020-18195No exploit | Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via thpluck-cms · pluck · CWE-352 | High8.8 | — | 0.9% | May 17, 2021 |
35Monitor | CVE-2022-27432No exploit | A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this featurpluck-cms · pluck · CWE-352 | High8.8 | — | 0.6% | Mar 29, 2022 |
35Monitor | CVE-2018-16634No exploit | Pluck v4.7.7 allows CSRF via admin.php?action=settings.pluck-cms · pluck · CWE-352 | High8.8 | — | 0.5% | Dec 4, 2018 |
33Monitor | CVE-2021-27984No exploit | In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.pluck-cms · pluck · CWE-434 | High8.1 | — | 2.5% | Dec 10, 2021 |
32Monitor | CVE-2009-1765Proof of concept | Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and executepluck-cms · pluck · CWE-22 | Medium6.8 | — | 15.0% | May 22, 2009 |
30Monitor | CVE-2020-20969Proof of concept | File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.pluck-cms · pluck · CWE-434 | High7.2 | — | 6.2% | Jun 20, 2023 |
30Monitor | CVE-2021-31745No exploit | Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform.pluck-cms · pluck · CWE-384 | High7.5 | — | 1.2% | Dec 10, 2021 |
29Monitor | CVE-2019-9050No exploit | An issue was discovered in Pluck 4.7.9-dev1.pluck-cms · pluck · CWE-434 | High7.2 | — | 2.0% | Feb 23, 2019 |
28Monitor | CVE-2008-6253Proof of concept | Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers tpluck-cms · pluck · CWE-22 | Medium6.8 | — | 5.0% | Feb 24, 2009 |
28Monitor | CVE-2008-6842Proof of concept | Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute apluck-cms · pluck · CWE-22 | Medium6.8 | — | 1.9% | Jul 2, 2009 |
28Monitor | CVE-2023-25828No exploit | Authenticate Remote Code Execution in Pluck CMSpluck-cms · pluck · CWE-434 | High7.2 | — | 1.6% | Mar 27, 2023 |
- CVE-2023-5056444Plan
An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary
HighCVSS 8.8Proof of conceptEPSS 29%pluck-cms · pluckDec 14, 2023
- CVE-2018-1173642Plan
An issue was discovered in Pluck before 4.7.7-dev2.
CriticalCVSS 9.8Proof of conceptEPSS 9%pluck-cms · pluckJun 5, 2018
- CVE-2020-2095140Plan
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
CriticalCVSS 9.8No exploitEPSS 4%pluck-cms · pluckMay 18, 2021
- CVE-2019-1134440Plan
data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler
CriticalCVSS 9.8No exploitEPSS 4%pluck-cms · pluckApr 19, 2019
- CVE-2014-870840Plan
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
CriticalCVSS 9.8No exploitEPSS 3%pluck-cms · pluckMar 17, 2017
- CVE-2021-3174640Plan
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal
CriticalCVSS 9.8No exploitEPSS 2%pluck-cms · pluckDec 10, 2021
- CVE-2018-1133140Plan
An issue was discovered in Pluck before 4.7.6.
CriticalCVSS 9.8No exploitEPSS 2%pluck-cms · pluckMay 21, 2018
- CVE-2019-101006240Plan
PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type.
CriticalCVSS 9.8No exploitEPSS 2%pluck-cms · pluckcmsJul 16, 2019
- CVE-2022-2696539Monitor
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.
HighCVSS 7.2Proof of conceptEPSS 36%pluck-cms · pluckMar 18, 2022
- CVE-2020-2071839Monitor
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to t
CriticalCVSS 9.8No exploitEPSS 1%pluck-cms · pluckcmsJun 20, 2023
- CVE-2024-4304239Monitor
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
CriticalCVSS 9.8No exploitEPSS 1%pluck-cms · pluckAug 16, 2024
- CVE-2020-2960738Monitor
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through
HighCVSS 7.2Proof of conceptEPSS 33%pluck-cms · pluckDec 16, 2020
- CVE-2020-2156436Monitor
An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11.
HighCVSS 8.8No exploitEPSS 3%pluck-cms · pluckSep 30, 2020
- CVE-2020-1819835Monitor
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the c
HighCVSS 8.8No exploitEPSS 1%pluck-cms · pluckMay 17, 2021
- CVE-2020-1819535Monitor
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via th
HighCVSS 8.8No exploitEPSS 1%pluck-cms · pluckMay 17, 2021
- CVE-2022-2743235Monitor
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this featur
HighCVSS 8.8No exploitEPSS 1%pluck-cms · pluckMar 29, 2022
- CVE-2018-1663435Monitor
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
HighCVSS 8.8No exploitEPSS 1%pluck-cms · pluckDec 4, 2018
- CVE-2021-2798433Monitor
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
HighCVSS 8.1No exploitEPSS 3%pluck-cms · pluckDec 10, 2021
- CVE-2009-176532Monitor
Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute
MediumCVSS 6.8Proof of conceptEPSS 15%pluck-cms · pluckMay 22, 2009
- CVE-2020-2096930Monitor
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
HighCVSS 7.2Proof of conceptEPSS 6%pluck-cms · pluckJun 20, 2023
- CVE-2021-3174530Monitor
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform.
HighCVSS 7.5No exploitEPSS 1%pluck-cms · pluckDec 10, 2021
- CVE-2019-905029Monitor
An issue was discovered in Pluck 4.7.9-dev1.
HighCVSS 7.2No exploitEPSS 2%pluck-cms · pluckFeb 23, 2019
- CVE-2008-625328Monitor
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers t
MediumCVSS 6.8Proof of conceptEPSS 5%pluck-cms · pluckFeb 24, 2009
- CVE-2008-684228Monitor
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute a
MediumCVSS 6.8Proof of conceptEPSS 2%pluck-cms · pluckJul 2, 2009
- CVE-2023-2582828Monitor
Authenticate Remote Code Execution in Pluck CMS
HighCVSS 7.2No exploitEPSS 2%pluck-cms · pluckMar 27, 2023