pluck-cms kayıtları
pluck-cms üreticisine ait 46 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 12
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type16
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-384 Session Fixation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
46 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2023-50564Kavram kanıtı | An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary pluck-cms · pluck · CWE-434 | Yüksek8,8 | — | %29,1 | 14 Ara 2023 |
42Planlayın | CVE-2018-11736Kavram kanıtı | An issue was discovered in Pluck before 4.7.7-dev2.pluck-cms · pluck · CWE-434 | Kritik9,8 | — | %8,6 | 5 Haz 2018 |
40Planlayın | CVE-2020-20951İstismar yok | In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.pluck-cms · pluck · CWE-77 | Kritik9,8 | — | %4,0 | 18 May 2021 |
40Planlayın | CVE-2019-11344İstismar yok | data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler pluck-cms · pluck · CWE-434 | Kritik9,8 | — | %3,6 | 19 Nis 2019 |
40Planlayın | CVE-2014-8708İstismar yok | Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.pluck-cms · pluck · CWE-264 | Kritik9,8 | — | %3,0 | 17 Mar 2017 |
40Planlayın | CVE-2021-31746İstismar yok | Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal pluck-cms · pluck · CWE-22 | Kritik9,8 | — | %2,4 | 10 Ara 2021 |
40Planlayın | CVE-2018-11331İstismar yok | An issue was discovered in Pluck before 4.7.6.pluck-cms · pluck · CWE-434 | Kritik9,8 | — | %2,2 | 21 May 2018 |
40Planlayın | CVE-2019-1010062İstismar yok | PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type.pluck-cms · pluckcms · CWE-434 | Kritik9,8 | — | %1,8 | 16 Tem 2019 |
39İzleyin | CVE-2022-26965Kavram kanıtı | In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.pluck-cms · pluck · CWE-434 | Yüksek7,2 | — | %36,3 | 18 Mar 2022 |
39İzleyin | CVE-2020-20718İstismar yok | File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to tpluck-cms · pluckcms · CWE-434 | Kritik9,8 | — | %1,3 | 20 Haz 2023 |
39İzleyin | CVE-2024-43042İstismar yok | Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.pluck-cms · pluck · CWE-307 | Kritik9,8 | — | %0,6 | 16 Ağu 2024 |
38İzleyin | CVE-2020-29607Kavram kanıtı | A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host throughpluck-cms · pluck · CWE-434 | Yüksek7,2 | — | %33,2 | 16 Ara 2020 |
36İzleyin | CVE-2020-21564İstismar yok | An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11.pluck-cms · pluck · CWE-434 | Yüksek8,8 | — | %3,5 | 30 Eyl 2020 |
35İzleyin | CVE-2020-18198İstismar yok | Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the cpluck-cms · pluck · CWE-352 | Yüksek8,8 | — | %0,9 | 17 May 2021 |
35İzleyin | CVE-2020-18195İstismar yok | Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via thpluck-cms · pluck · CWE-352 | Yüksek8,8 | — | %0,9 | 17 May 2021 |
35İzleyin | CVE-2022-27432İstismar yok | A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this featurpluck-cms · pluck · CWE-352 | Yüksek8,8 | — | %0,6 | 29 Mar 2022 |
35İzleyin | CVE-2018-16634İstismar yok | Pluck v4.7.7 allows CSRF via admin.php?action=settings.pluck-cms · pluck · CWE-352 | Yüksek8,8 | — | %0,5 | 4 Ara 2018 |
33İzleyin | CVE-2021-27984İstismar yok | In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.pluck-cms · pluck · CWE-434 | Yüksek8,1 | — | %2,5 | 10 Ara 2021 |
32İzleyin | CVE-2009-1765Kavram kanıtı | Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and executepluck-cms · pluck · CWE-22 | Orta6,8 | — | %15,0 | 22 May 2009 |
30İzleyin | CVE-2020-20969Kavram kanıtı | File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.pluck-cms · pluck · CWE-434 | Yüksek7,2 | — | %6,2 | 20 Haz 2023 |
30İzleyin | CVE-2021-31745İstismar yok | Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform.pluck-cms · pluck · CWE-384 | Yüksek7,5 | — | %1,2 | 10 Ara 2021 |
29İzleyin | CVE-2019-9050İstismar yok | An issue was discovered in Pluck 4.7.9-dev1.pluck-cms · pluck · CWE-434 | Yüksek7,2 | — | %2,0 | 23 Şub 2019 |
28İzleyin | CVE-2008-6253Kavram kanıtı | Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers tpluck-cms · pluck · CWE-22 | Orta6,8 | — | %5,0 | 24 Şub 2009 |
28İzleyin | CVE-2008-6842Kavram kanıtı | Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute apluck-cms · pluck · CWE-22 | Orta6,8 | — | %1,9 | 2 Tem 2009 |
28İzleyin | CVE-2023-25828İstismar yok | Authenticate Remote Code Execution in Pluck CMSpluck-cms · pluck · CWE-434 | Yüksek7,2 | — | %1,6 | 27 Mar 2023 |
- CVE-2023-5056444Planlayın
An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary
YüksekCVSS 8,8Kavram kanıtıEPSS %29pluck-cms · pluck14 Ara 2023
- CVE-2018-1173642Planlayın
An issue was discovered in Pluck before 4.7.7-dev2.
KritikCVSS 9,8Kavram kanıtıEPSS %9pluck-cms · pluck5 Haz 2018
- CVE-2020-2095140Planlayın
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
KritikCVSS 9,8İstismar yokEPSS %4pluck-cms · pluck18 May 2021
- CVE-2019-1134440Planlayın
data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler
KritikCVSS 9,8İstismar yokEPSS %4pluck-cms · pluck19 Nis 2019
- CVE-2014-870840Planlayın
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
KritikCVSS 9,8İstismar yokEPSS %3pluck-cms · pluck17 Mar 2017
- CVE-2021-3174640Planlayın
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal
KritikCVSS 9,8İstismar yokEPSS %2pluck-cms · pluck10 Ara 2021
- CVE-2018-1133140Planlayın
An issue was discovered in Pluck before 4.7.6.
KritikCVSS 9,8İstismar yokEPSS %2pluck-cms · pluck21 May 2018
- CVE-2019-101006240Planlayın
PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type.
KritikCVSS 9,8İstismar yokEPSS %2pluck-cms · pluckcms16 Tem 2019
- CVE-2022-2696539İzleyin
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.
YüksekCVSS 7,2Kavram kanıtıEPSS %36pluck-cms · pluck18 Mar 2022
- CVE-2020-2071839İzleyin
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to t
KritikCVSS 9,8İstismar yokEPSS %1pluck-cms · pluckcms20 Haz 2023
- CVE-2024-4304239İzleyin
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
KritikCVSS 9,8İstismar yokEPSS %1pluck-cms · pluck16 Ağu 2024
- CVE-2020-2960738İzleyin
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through
YüksekCVSS 7,2Kavram kanıtıEPSS %33pluck-cms · pluck16 Ara 2020
- CVE-2020-2156436İzleyin
An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11.
YüksekCVSS 8,8İstismar yokEPSS %3pluck-cms · pluck30 Eyl 2020
- CVE-2020-1819835İzleyin
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the c
YüksekCVSS 8,8İstismar yokEPSS %1pluck-cms · pluck17 May 2021
- CVE-2020-1819535İzleyin
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via th
YüksekCVSS 8,8İstismar yokEPSS %1pluck-cms · pluck17 May 2021
- CVE-2022-2743235İzleyin
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this featur
YüksekCVSS 8,8İstismar yokEPSS %1pluck-cms · pluck29 Mar 2022
- CVE-2018-1663435İzleyin
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
YüksekCVSS 8,8İstismar yokEPSS %1pluck-cms · pluck4 Ara 2018
- CVE-2021-2798433İzleyin
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
YüksekCVSS 8,1İstismar yokEPSS %3pluck-cms · pluck10 Ara 2021
- CVE-2009-176532İzleyin
Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute
OrtaCVSS 6,8Kavram kanıtıEPSS %15pluck-cms · pluck22 May 2009
- CVE-2020-2096930İzleyin
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
YüksekCVSS 7,2Kavram kanıtıEPSS %6pluck-cms · pluck20 Haz 2023
- CVE-2021-3174530İzleyin
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform.
YüksekCVSS 7,5İstismar yokEPSS %1pluck-cms · pluck10 Ara 2021
- CVE-2019-905029İzleyin
An issue was discovered in Pluck 4.7.9-dev1.
YüksekCVSS 7,2İstismar yokEPSS %2pluck-cms · pluck23 Şub 2019
- CVE-2008-625328İzleyin
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers t
OrtaCVSS 6,8Kavram kanıtıEPSS %5pluck-cms · pluck24 Şub 2009
- CVE-2008-684228İzleyin
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute a
OrtaCVSS 6,8Kavram kanıtıEPSS %2pluck-cms · pluck2 Tem 2009
- CVE-2023-2582828İzleyin
Authenticate Remote Code Execution in Pluck CMS
YüksekCVSS 7,2İstismar yokEPSS %2pluck-cms · pluck27 Mar 2023