Vulnerability index

Browse CVEs

41 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-46099 In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the mo… Pluck Mitigation only Fix from $1,9502025-07-23 CRITICAL 9.8 CVE-2024-43042 Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack. Pluck No fix yet Fix from $2,3002024-08-16 HIGH 8.8 CVE-2023-50564EPSS 29% An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via … Pluck No fix yet Fix from $1,9502023-12-14 MEDIUM 5.4 CVE-2023-5013 A vulnerability has been found in Pluck CMS 4.7.18 and classified as problematic. This vulnerability affects unknown code of the file install.php of … Pluck No fix yet Fix from $1,6002023-09-16 HIGH 7.2 CVE-2023-27083 An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality. Pluck 4.7.16+ Fix from $1,9502023-06-22 CRITICAL 9.8 CVE-2020-20718 File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the sa… Pluckcms Patch available Fix from $2,3002023-06-20 HIGH 7.2 CVE-2020-20918 An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when edit… Pluck Patch available Fix from $1,9502023-06-20 HIGH 7.2 CVE-2020-20919 File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the them… Pluck No fix yet Fix from $1,9502023-06-20 HIGH 7.2 CVE-2020-20969EPSS 6% File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file. Pluck Patch available Fix from $1,9502023-06-20 HIGH 7.2 CVE-2023-25828 Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collecti… Pluck 4.7.16+ Fix from $1,9502023-03-27 MEDIUM 6.5 CVE-2022-26589 A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages. Pluck Mitigation only Fix from $1,6002022-04-13 HIGH 8.8 CVE-2022-27432 A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading… Pluck No fix yet Fix from $1,9502022-03-30 HIGH 7.2 CVE-2022-26965EPSS 36% In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution. Pluck No fix yet Fix from $1,9502022-03-18 HIGH 8.1 CVE-2021-27984 In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files. Pluck No fix yet Fix from $1,9502021-12-10 CRITICAL 9.8 CVE-2021-31746 Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and poten… Pluck No fix yet Fix from $2,3002021-12-10 HIGH 7.5 CVE-2021-31745 Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluc… Pluck No fix yet Fix from $1,9502021-12-10 CRITICAL 9.8 CVE-2020-20951 In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files. Pluck No fix yet Fix from $2,3002021-05-18 HIGH 8.8 CVE-2020-18195 Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the compone… Pluck No fix yet Fix from $1,9502021-05-17 HIGH 8.8 CVE-2020-18198 Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component … Pluck No fix yet Fix from $1,9502021-05-17 HIGH 7.2 CVE-2020-29607EPSS 33% A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "man… Pluck 4.7.13+ Fix from $1,9502020-12-16 HIGH 8.8 CVE-2020-21564 An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin… Pluck No fix yet Fix from $1,9502020-09-30 CRITICAL 9.8 CVE-2019-1010062 PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type. The impact is: get webshell. The component is: da… Pluckcms after 4.7.4 Fix from $2,3002019-07-16 CRITICAL 9.8 CVE-2019-11344 data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-p… Pluck No fix yet Fix from $2,3002019-04-19 HIGH 7.2 CVE-2019-9050 An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive… Pluck No fix yet Fix from $1,9502019-02-23 MEDIUM 6.5 CVE-2019-9048 An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&v… Pluck No fix yet Fix from $1,6002019-02-23 MEDIUM 6.5 CVE-2019-9049 An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI. Pluck No fix yet Fix from $1,6002019-02-23 MEDIUM 6.5 CVE-2019-9051 An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI. Pluck No fix yet Fix from $1,6002019-02-23 MEDIUM 6.5 CVE-2019-9052 An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI. Pluck No fix yet Fix from $1,6002019-02-23 HIGH 8.8 CVE-2018-16634 Pluck v4.7.7 allows CSRF via admin.php?action=settings. Pluck No fix yet Fix from $1,9502018-12-04 MEDIUM 5.4 CVE-2018-16633 Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title. Pluck No fix yet Fix from $1,6002018-12-04