PluXml kayıtları
pluxml üreticisine ait 23 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-384 Session Fixation1
- CWE-20 Improper Input Validation1
- CWE-804 Guessable CAPTCHA1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
23 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-18185İstismar yok | class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.pluxml · pluxml · CWE-94 | Kritik9,8 | — | %1,8 | 2 Eki 2020 |
39İzleyin | CVE-2024-48138İstismar yok | A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows atCWE-94 | Kritik9,8 | — | %0,9 | 29 Eki 2024 |
36İzleyin | CVE-2022-25018Kavram kanıtı | Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.pluxml · pluxml · CWE-94 | Yüksek8,8 | — | %2,7 | 28 Şub 2022 |
35İzleyin | CVE-2024-22636İstismar yok | PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature.pluxml · pluxml | Yüksek8,8 | — | %1,3 | 25 Oca 2024 |
33İzleyin | CVE-2012-2227Kavram kanıtı | Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local pluxml · pluxml · CWE-22 | Yüksek7,5 | — | %9,8 | 26 Ağu 2012 |
32İzleyin | CVE-2007-3432Kavram kanıtı | Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code pluxml · pluxml | Yüksek7,5 | — | %8,2 | 26 Haz 2007 |
26İzleyin | CVE-2025-67436İstismar yok | Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP pluxml · pluxml · CWE-77 | Orta6,5 | — | %0,6 | 22 Ara 2025 |
24İzleyin | CVE-2025-70128İstismar yok | A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier.pluxml · pluxml · CWE-79 | Orta6,1 | — | %0,2 | 10 Mar 2026 |
21İzleyin | CVE-2022-25020Kavram kanıtı | A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload pluxml · pluxml · CWE-79 | Orta5,4 | — | %1,2 | 28 Şub 2022 |
21İzleyin | CVE-2022-24585İstismar yok | A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbipluxml · pluxml · CWE-79 | Orta5,4 | — | %0,7 | 15 Şub 2022 |
21İzleyin | CVE-2022-24586İstismar yok | A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute apluxml · pluxml · CWE-79 | Orta5,4 | — | %0,7 | 15 Şub 2022 |
21İzleyin | CVE-2022-24587İstismar yok | A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitrpluxml · pluxml · CWE-79 | Orta5,4 | — | %0,7 | 15 Şub 2022 |
21İzleyin | CVE-2017-1001001İstismar yok | PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalatpluxml · pluxml · CWE-79 | Orta5,4 | — | %0,6 | 1 Kas 2017 |
21İzleyin | CVE-2025-70129İstismar yok | If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format thatpluxml · pluxml · CWE-804 | Orta5,3 | — | %0,3 | 10 Mar 2026 |
20İzleyin | CVE-2012-4674İstismar yok | PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.pluxml · pluxml · CWE-200 | Orta5,0 | — | %1,2 | 26 Ağu 2012 |
20İzleyin | CVE-2026-24351İstismar yok | Stored XSS in PluXml CMSpluxml · pluxml · CWE-79 | Orta5,1 | — | %0,2 | 27 Şub 2026 |
20İzleyin | CVE-2026-24350İstismar yok | Stored XSS in PluXml CMSpluxml · pluxml · CWE-79 | Orta5,1 | — | %0,2 | 27 Şub 2026 |
19İzleyin | CVE-2021-38603Kavram kanıtı | PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.pluxml · pluxml · CWE-79 | Orta4,8 | — | %1,1 | 12 Ağu 2021 |
19İzleyin | CVE-2021-38602Kavram kanıtı | PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.pluxml · pluxml · CWE-79 | Orta4,8 | — | %0,8 | 12 Ağu 2021 |
19İzleyin | CVE-2026-24352İstismar yok | Session Fixation in PluXml CMSpluxml · pluxml · CWE-384 | Orta4,8 | — | %0,4 | 27 Şub 2026 |
18İzleyin | CVE-2007-3542Kavram kanıtı | Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML vipluxml · pluxml | Orta4,3 | — | %1,9 | 3 Tem 2007 |
17İzleyin | CVE-2012-4675İstismar yok | Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectpluxml · pluxml · CWE-79 | Orta4,3 | — | %1,2 | 26 Ağu 2012 |
8İzleyin | CVE-2025-15438İstismar yok | PluXml Media Management medias.php __destruct deserializationpluxml · pluxml · CWE-20 | Düşük2,0 | — | %0,5 | 2 Oca 2026 |
- CVE-2020-1818540Planlayın
class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.
KritikCVSS 9,8İstismar yokEPSS %2pluxml · pluxml2 Eki 2020
- CVE-2024-4813839İzleyin
A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows at
KritikCVSS 9,8İstismar yokEPSS %129 Eki 2024
- CVE-2022-2501836İzleyin
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.
YüksekCVSS 8,8Kavram kanıtıEPSS %3pluxml · pluxml28 Şub 2022
- CVE-2024-2263635İzleyin
PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature.
YüksekCVSS 8,8İstismar yokEPSS %1pluxml · pluxml25 Oca 2024
- CVE-2012-222733İzleyin
Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local
YüksekCVSS 7,5Kavram kanıtıEPSS %10pluxml · pluxml26 Ağu 2012
- CVE-2007-343232İzleyin
Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code
YüksekCVSS 7,5Kavram kanıtıEPSS %8pluxml · pluxml26 Haz 2007
- CVE-2025-6743626İzleyin
Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP
OrtaCVSS 6,5İstismar yokEPSS %1pluxml · pluxml22 Ara 2025
- CVE-2025-7012824İzleyin
A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier.
OrtaCVSS 6,1İstismar yokEPSS %0pluxml · pluxml10 Mar 2026
- CVE-2022-2502021İzleyin
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload
OrtaCVSS 5,4Kavram kanıtıEPSS %1pluxml · pluxml28 Şub 2022
- CVE-2022-2458521İzleyin
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbi
OrtaCVSS 5,4İstismar yokEPSS %1pluxml · pluxml15 Şub 2022
- CVE-2022-2458621İzleyin
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute a
OrtaCVSS 5,4İstismar yokEPSS %1pluxml · pluxml15 Şub 2022
- CVE-2022-2458721İzleyin
A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitr
OrtaCVSS 5,4İstismar yokEPSS %1pluxml · pluxml15 Şub 2022
- CVE-2017-100100121İzleyin
PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalat
OrtaCVSS 5,4İstismar yokEPSS %1pluxml · pluxml1 Kas 2017
- CVE-2025-7012921İzleyin
If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that
OrtaCVSS 5,3İstismar yokEPSS %0pluxml · pluxml10 Mar 2026
- CVE-2012-467420İzleyin
PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.
OrtaCVSS 5,0İstismar yokEPSS %1pluxml · pluxml26 Ağu 2012
- CVE-2026-2435120İzleyin
Stored XSS in PluXml CMS
OrtaCVSS 5,1İstismar yokEPSS %0pluxml · pluxml27 Şub 2026
- CVE-2026-2435020İzleyin
Stored XSS in PluXml CMS
OrtaCVSS 5,1İstismar yokEPSS %0pluxml · pluxml27 Şub 2026
- CVE-2021-3860319İzleyin
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.
OrtaCVSS 4,8Kavram kanıtıEPSS %1pluxml · pluxml12 Ağu 2021
- CVE-2021-3860219İzleyin
PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.
OrtaCVSS 4,8Kavram kanıtıEPSS %1pluxml · pluxml12 Ağu 2021
- CVE-2026-2435219İzleyin
Session Fixation in PluXml CMS
OrtaCVSS 4,8İstismar yokEPSS %0pluxml · pluxml27 Şub 2026
- CVE-2007-354218İzleyin
Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML vi
OrtaCVSS 4,3Kavram kanıtıEPSS %2pluxml · pluxml3 Tem 2007
- CVE-2012-467517İzleyin
Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vect
OrtaCVSS 4,3İstismar yokEPSS %1pluxml · pluxml26 Ağu 2012
- CVE-2025-154388İzleyin
PluXml Media Management medias.php __destruct deserialization
DüşükCVSS 2,0İstismar yokEPSS %0pluxml · pluxml2 Oca 2026