Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-24352 PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This… Pluxml Mitigation only Fix from $2,3002026-02-27 MEDIUM 5.4 CVE-2026-24351 PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into … Pluxml Mitigation only Fix from $1,6002026-02-27 MEDIUM 5.4 CVE-2026-24350 PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious paylo… Pluxml Mitigation only Fix from $1,6002026-02-27 MEDIUM 6.5 CVE-2025-67436 Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell … Pluxml No fix yet Fix from $1,6002025-12-22 HIGH 8.8 CVE-2024-22636 PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited… Pluxml No fix yet Fix from $1,9502024-01-25 HIGH 8.8 CVE-2022-25018 Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages. Pluxml Mitigation only Fix from $1,9502022-03-01 MEDIUM 5.4 CVE-2022-25020 A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the th… Pluxml No fix yet Fix from $1,6002022-03-01 MEDIUM 5.4 CVE-2022-24585 A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbitrary web… Pluxml No fix yet Fix from $1,6002022-02-15 MEDIUM 5.4 CVE-2022-24587 A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitrary web s… Pluxml No fix yet Fix from $1,6002022-02-15 MEDIUM 5.4 CVE-2022-24586 A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary … Pluxml No fix yet Fix from $1,6002022-02-15 CRITICAL 9.8 CVE-2020-18185 class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment. Pluxml No fix yet Fix from $2,3002020-10-02 MEDIUM 5.4 CVE-2017-1001001 PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of pr… Pluxml Mitigation only Fix from $1,6002017-11-01 HIGH 7.5 CVE-2007-3432EPSS 8% Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jp… Pluxml No fix yet Fix from $1,9502007-06-27