Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pluxml MEDIUM 6.1
CVE-2025-70128

A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The applicati…

Fix: after 5.8.22
Fix from $1,600 2026-03-10
Pluxml MEDIUM 5.3
CVE-2025-70129

If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be a…

Fix: after 5.8.22
Fix from $1,600 2026-03-10
Pluxml CRITICAL 9.8
CVE-2026-24352

PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This…

Mitigation only
Fix from $2,300 2026-02-27
Pluxml MEDIUM 5.4
CVE-2026-24351

PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into …

Mitigation only
Fix from $1,600 2026-02-27
Pluxml MEDIUM 5.4
CVE-2026-24350

PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious paylo…

Mitigation only
Fix from $1,600 2026-02-27
Pluxml HIGH 7.2
CVE-2025-15438

A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the co…

Fix: after 5.8.22
Fix from $1,950 2026-01-02
Pluxml MEDIUM 6.5
CVE-2025-67436

Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell …

No fix yet
Fix from $1,600 2025-12-22
Pluxml HIGH 8.8
CVE-2024-22636

PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited…

No fix yet
Fix from $1,950 2024-01-25
Pluxml HIGH 8.8
CVE-2022-25018

Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

Mitigation only
Fix from $1,950 2022-03-01
Pluxml MEDIUM 5.4
CVE-2022-25020

A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the th…

No fix yet
Fix from $1,600 2022-03-01
Pluxml MEDIUM 5.4
CVE-2022-24585

A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbitrary web…

No fix yet
Fix from $1,600 2022-02-15
Pluxml MEDIUM 5.4
CVE-2022-24587

A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitrary web s…

No fix yet
Fix from $1,600 2022-02-15
Pluxml MEDIUM 5.4
CVE-2022-24586

A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary …

No fix yet
Fix from $1,600 2022-02-15
Pluxml CRITICAL 9.8
CVE-2020-18185

class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.

No fix yet
Fix from $2,300 2020-10-02
Pluxml MEDIUM 5.4
CVE-2017-1001001

PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of pr…

Mitigation only
Fix from $1,600 2017-11-01
Pluxml HIGH 7.5
CVE-2012-2227EPSS 10%

Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via…

Fix: after 5.1.5
Fix from $1,950 2012-08-26
Pluxml MEDIUM 5.0
CVE-2012-4674

PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.

Fix: after 5.1.5
Fix from $1,600 2012-08-26
Pluxml HIGH 7.5
CVE-2007-3432EPSS 8%

Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jp…

No fix yet
Fix from $1,950 2007-06-27