Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-70128
A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The applicati…
Pluxml
after 5.8.22
MEDIUM 5.3
CVE-2025-70129
If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be a…
Pluxml
after 5.8.22
CRITICAL 9.8
CVE-2026-24352
PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This…
Pluxml
Mitigation only
MEDIUM 5.4
CVE-2026-24351
PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into …
Pluxml
Mitigation only
MEDIUM 5.4
CVE-2026-24350
PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious paylo…
Pluxml
Mitigation only
HIGH 7.2
CVE-2025-15438
A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the co…
Pluxml
after 5.8.22
MEDIUM 6.5
CVE-2025-67436
Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell …
Pluxml
No fix yet
HIGH 8.8
CVE-2024-22636
PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited…
Pluxml
No fix yet
HIGH 8.8
CVE-2022-25018
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.
Pluxml
Mitigation only
MEDIUM 5.4
CVE-2022-25020
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the th…
Pluxml
No fix yet
MEDIUM 5.4
CVE-2022-24585
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbitrary web…
Pluxml
No fix yet
MEDIUM 5.4
CVE-2022-24587
A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitrary web s…
Pluxml
No fix yet
MEDIUM 5.4
CVE-2022-24586
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary …
Pluxml
No fix yet
CRITICAL 9.8
CVE-2020-18185
class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.
Pluxml
No fix yet
MEDIUM 5.4
CVE-2017-1001001
PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of pr…
Pluxml
Mitigation only
HIGH 7.5
CVE-2012-2227EPSS 10%
Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via…
Pluxml
after 5.1.5
MEDIUM 5.0
CVE-2012-4674
PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.
Pluxml
after 5.1.5
HIGH 7.5
CVE-2007-3432EPSS 8%
Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jp…
Pluxml
No fix yet