İçeriğe atla
Noroxi

pluck-cms kayıtları

pluck-cms üreticisine ait 46 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
12
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

46 kayıt
  • CVE-2023-50564
    44Planlayın

    An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary

    YüksekCVSS 8,8Kavram kanıtıEPSS %29

    pluck-cms · pluck14 Ara 2023

  • CVE-2018-11736
    42Planlayın

    An issue was discovered in Pluck before 4.7.7-dev2.

    KritikCVSS 9,8Kavram kanıtıEPSS %9

    pluck-cms · pluck5 Haz 2018

  • CVE-2020-20951
    40Planlayın

    In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.

    KritikCVSS 9,8İstismar yokEPSS %4

    pluck-cms · pluck18 May 2021

  • CVE-2019-11344
    40Planlayın

    data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler

    KritikCVSS 9,8İstismar yokEPSS %4

    pluck-cms · pluck19 Nis 2019

  • CVE-2014-8708
    40Planlayın

    Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.

    KritikCVSS 9,8İstismar yokEPSS %3

    pluck-cms · pluck17 Mar 2017

  • CVE-2021-31746
    40Planlayın

    Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal

    KritikCVSS 9,8İstismar yokEPSS %2

    pluck-cms · pluck10 Ara 2021

  • CVE-2018-11331
    40Planlayın

    An issue was discovered in Pluck before 4.7.6.

    KritikCVSS 9,8İstismar yokEPSS %2

    pluck-cms · pluck21 May 2018

  • CVE-2019-1010062
    40Planlayın

    PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type.

    KritikCVSS 9,8İstismar yokEPSS %2

    pluck-cms · pluckcms16 Tem 2019

  • CVE-2022-26965
    39İzleyin

    In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.

    YüksekCVSS 7,2Kavram kanıtıEPSS %36

    pluck-cms · pluck18 Mar 2022

  • CVE-2020-20718
    39İzleyin

    File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to t

    KritikCVSS 9,8İstismar yokEPSS %1

    pluck-cms · pluckcms20 Haz 2023

  • CVE-2024-43042
    39İzleyin

    Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.

    KritikCVSS 9,8İstismar yokEPSS %1

    pluck-cms · pluck16 Ağu 2024

  • CVE-2020-29607
    38İzleyin

    A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through

    YüksekCVSS 7,2Kavram kanıtıEPSS %33

    pluck-cms · pluck16 Ara 2020

  • CVE-2020-21564
    36İzleyin

    An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11.

    YüksekCVSS 8,8İstismar yokEPSS %3

    pluck-cms · pluck30 Eyl 2020

  • CVE-2020-18198
    35İzleyin

    Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the c

    YüksekCVSS 8,8İstismar yokEPSS %1

    pluck-cms · pluck17 May 2021

  • CVE-2020-18195
    35İzleyin

    Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via th

    YüksekCVSS 8,8İstismar yokEPSS %1

    pluck-cms · pluck17 May 2021

  • CVE-2022-27432
    35İzleyin

    A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this featur

    YüksekCVSS 8,8İstismar yokEPSS %1

    pluck-cms · pluck29 Mar 2022

  • CVE-2018-16634
    35İzleyin

    Pluck v4.7.7 allows CSRF via admin.php?action=settings.

    YüksekCVSS 8,8İstismar yokEPSS %1

    pluck-cms · pluck4 Ara 2018

  • CVE-2021-27984
    33İzleyin

    In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.

    YüksekCVSS 8,1İstismar yokEPSS %3

    pluck-cms · pluck10 Ara 2021

  • CVE-2009-1765
    32İzleyin

    Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute

    OrtaCVSS 6,8Kavram kanıtıEPSS %15

    pluck-cms · pluck22 May 2009

  • CVE-2020-20969
    30İzleyin

    File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.

    YüksekCVSS 7,2Kavram kanıtıEPSS %6

    pluck-cms · pluck20 Haz 2023

  • CVE-2021-31745
    30İzleyin

    Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform.

    YüksekCVSS 7,5İstismar yokEPSS %1

    pluck-cms · pluck10 Ara 2021

  • CVE-2019-9050
    29İzleyin

    An issue was discovered in Pluck 4.7.9-dev1.

    YüksekCVSS 7,2İstismar yokEPSS %2

    pluck-cms · pluck23 Şub 2019

  • CVE-2008-6253
    28İzleyin

    Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers t

    OrtaCVSS 6,8Kavram kanıtıEPSS %5

    pluck-cms · pluck24 Şub 2009

  • CVE-2008-6842
    28İzleyin

    Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute a

    OrtaCVSS 6,8Kavram kanıtıEPSS %2

    pluck-cms · pluck2 Tem 2009

  • CVE-2023-25828
    28İzleyin

    Authenticate Remote Code Execution in Pluck CMS

    YüksekCVSS 7,2İstismar yokEPSS %2

    pluck-cms · pluck27 Mar 2023