Перейти к содержимому
Noroxi

Записи PluXml

23 опубликованных записей вендора pluxml.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
4
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

23 записей
  • CVE-2020-18185
    40В плане

    class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    pluxml · pluxml2 окт. 2020 г.

  • CVE-2024-48138
    39Наблюдать

    A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows at

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    29 окт. 2024 г.

  • CVE-2022-25018
    36Наблюдать

    Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

    ВысокаяCVSS 8,8Proof of conceptEPSS 3 %

    pluxml · pluxml28 февр. 2022 г.

  • CVE-2024-22636
    35Наблюдать

    PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    pluxml · pluxml25 янв. 2024 г.

  • CVE-2012-2227
    33Наблюдать

    Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local

    ВысокаяCVSS 7,5Proof of conceptEPSS 10 %

    pluxml · pluxml26 авг. 2012 г.

  • CVE-2007-3432
    32Наблюдать

    Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code

    ВысокаяCVSS 7,5Proof of conceptEPSS 8 %

    pluxml · pluxml26 июн. 2007 г.

  • CVE-2025-67436
    26Наблюдать

    Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    pluxml · pluxml22 дек. 2025 г.

  • CVE-2025-70128
    24Наблюдать

    A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    pluxml · pluxml10 мар. 2026 г.

  • CVE-2022-25020
    21Наблюдать

    A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload

    СредняяCVSS 5,4Proof of conceptEPSS 1 %

    pluxml · pluxml28 февр. 2022 г.

  • CVE-2022-24585
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbi

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    pluxml · pluxml15 февр. 2022 г.

  • CVE-2022-24586
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute a

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    pluxml · pluxml15 февр. 2022 г.

  • CVE-2022-24587
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitr

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    pluxml · pluxml15 февр. 2022 г.

  • CVE-2017-1001001
    21Наблюдать

    PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalat

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    pluxml · pluxml1 нояб. 2017 г.

  • CVE-2025-70129
    21Наблюдать

    If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    pluxml · pluxml10 мар. 2026 г.

  • CVE-2012-4674
    20Наблюдать

    PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    pluxml · pluxml26 авг. 2012 г.

  • CVE-2026-24351
    20Наблюдать

    Stored XSS in PluXml CMS

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    pluxml · pluxml27 февр. 2026 г.

  • CVE-2026-24350
    20Наблюдать

    Stored XSS in PluXml CMS

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    pluxml · pluxml27 февр. 2026 г.

  • CVE-2021-38603
    19Наблюдать

    PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.

    СредняяCVSS 4,8Proof of conceptEPSS 1 %

    pluxml · pluxml12 авг. 2021 г.

  • CVE-2021-38602
    19Наблюдать

    PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.

    СредняяCVSS 4,8Proof of conceptEPSS 1 %

    pluxml · pluxml12 авг. 2021 г.

  • CVE-2026-24352
    19Наблюдать

    Session Fixation in PluXml CMS

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    pluxml · pluxml27 февр. 2026 г.

  • CVE-2007-3542
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML vi

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    pluxml · pluxml3 июл. 2007 г.

  • CVE-2012-4675
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vect

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    pluxml · pluxml26 авг. 2012 г.

  • CVE-2025-15438
    8Наблюдать

    PluXml Media Management medias.php __destruct deserialization

    НизкаяCVSS 2,0Эксплойта нетEPSS 0 %

    pluxml · pluxml2 янв. 2026 г.