İçeriğe atla
Noroxi

PluXml kayıtları

pluxml üreticisine ait 23 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
4
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

23 kayıt
  • CVE-2020-18185
    40Planlayın

    class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.

    KritikCVSS 9,8İstismar yokEPSS %2

    pluxml · pluxml2 Eki 2020

  • CVE-2024-48138
    39İzleyin

    A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows at

    KritikCVSS 9,8İstismar yokEPSS %1

    29 Eki 2024

  • CVE-2022-25018
    36İzleyin

    Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

    YüksekCVSS 8,8Kavram kanıtıEPSS %3

    pluxml · pluxml28 Şub 2022

  • CVE-2024-22636
    35İzleyin

    PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature.

    YüksekCVSS 8,8İstismar yokEPSS %1

    pluxml · pluxml25 Oca 2024

  • CVE-2012-2227
    33İzleyin

    Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local

    YüksekCVSS 7,5Kavram kanıtıEPSS %10

    pluxml · pluxml26 Ağu 2012

  • CVE-2007-3432
    32İzleyin

    Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code

    YüksekCVSS 7,5Kavram kanıtıEPSS %8

    pluxml · pluxml26 Haz 2007

  • CVE-2025-67436
    26İzleyin

    Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP

    OrtaCVSS 6,5İstismar yokEPSS %1

    pluxml · pluxml22 Ara 2025

  • CVE-2025-70128
    24İzleyin

    A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier.

    OrtaCVSS 6,1İstismar yokEPSS %0

    pluxml · pluxml10 Mar 2026

  • CVE-2022-25020
    21İzleyin

    A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload

    OrtaCVSS 5,4Kavram kanıtıEPSS %1

    pluxml · pluxml28 Şub 2022

  • CVE-2022-24585
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbi

    OrtaCVSS 5,4İstismar yokEPSS %1

    pluxml · pluxml15 Şub 2022

  • CVE-2022-24586
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute a

    OrtaCVSS 5,4İstismar yokEPSS %1

    pluxml · pluxml15 Şub 2022

  • CVE-2022-24587
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitr

    OrtaCVSS 5,4İstismar yokEPSS %1

    pluxml · pluxml15 Şub 2022

  • PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalat

    OrtaCVSS 5,4İstismar yokEPSS %1

    pluxml · pluxml1 Kas 2017

  • CVE-2025-70129
    21İzleyin

    If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that

    OrtaCVSS 5,3İstismar yokEPSS %0

    pluxml · pluxml10 Mar 2026

  • CVE-2012-4674
    20İzleyin

    PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.

    OrtaCVSS 5,0İstismar yokEPSS %1

    pluxml · pluxml26 Ağu 2012

  • CVE-2026-24351
    20İzleyin

    Stored XSS in PluXml CMS

    OrtaCVSS 5,1İstismar yokEPSS %0

    pluxml · pluxml27 Şub 2026

  • CVE-2026-24350
    20İzleyin

    Stored XSS in PluXml CMS

    OrtaCVSS 5,1İstismar yokEPSS %0

    pluxml · pluxml27 Şub 2026

  • CVE-2021-38603
    19İzleyin

    PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.

    OrtaCVSS 4,8Kavram kanıtıEPSS %1

    pluxml · pluxml12 Ağu 2021

  • CVE-2021-38602
    19İzleyin

    PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.

    OrtaCVSS 4,8Kavram kanıtıEPSS %1

    pluxml · pluxml12 Ağu 2021

  • CVE-2026-24352
    19İzleyin

    Session Fixation in PluXml CMS

    OrtaCVSS 4,8İstismar yokEPSS %0

    pluxml · pluxml27 Şub 2026

  • CVE-2007-3542
    18İzleyin

    Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML vi

    OrtaCVSS 4,3Kavram kanıtıEPSS %2

    pluxml · pluxml3 Tem 2007

  • CVE-2012-4675
    17İzleyin

    Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vect

    OrtaCVSS 4,3İstismar yokEPSS %1

    pluxml · pluxml26 Ağu 2012

  • PluXml Media Management medias.php __destruct deserialization

    DüşükCVSS 2,0İstismar yokEPSS %0

    pluxml · pluxml2 Oca 2026