Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-70128 A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The applicati… Pluxml after 5.8.22 Fix from $1,6002026-03-10 MEDIUM 5.3 CVE-2025-70129 If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be a… Pluxml after 5.8.22 Fix from $1,6002026-03-10 CRITICAL 9.8 CVE-2026-24352 PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This… Pluxml Mitigation only Fix from $2,3002026-02-27 MEDIUM 5.4 CVE-2026-24351 PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into … Pluxml Mitigation only Fix from $1,6002026-02-27 MEDIUM 5.4 CVE-2026-24350 PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious paylo… Pluxml Mitigation only Fix from $1,6002026-02-27 HIGH 7.2 CVE-2025-15438 A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the co… Pluxml after 5.8.22 Fix from $1,9502026-01-02 MEDIUM 6.5 CVE-2025-67436 Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell … Pluxml No fix yet Fix from $1,6002025-12-22 HIGH 8.8 CVE-2024-22636 PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited… Pluxml No fix yet Fix from $1,9502024-01-25 HIGH 8.8 CVE-2022-25018 Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages. Pluxml Mitigation only Fix from $1,9502022-03-01 MEDIUM 5.4 CVE-2022-25020 A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the th… Pluxml No fix yet Fix from $1,6002022-03-01 MEDIUM 5.4 CVE-2022-24585 A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbitrary web… Pluxml No fix yet Fix from $1,6002022-02-15 MEDIUM 5.4 CVE-2022-24587 A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitrary web s… Pluxml No fix yet Fix from $1,6002022-02-15 MEDIUM 5.4 CVE-2022-24586 A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary … Pluxml No fix yet Fix from $1,6002022-02-15 CRITICAL 9.8 CVE-2020-18185 class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment. Pluxml No fix yet Fix from $2,3002020-10-02 MEDIUM 5.4 CVE-2017-1001001 PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of pr… Pluxml Mitigation only Fix from $1,6002017-11-01 HIGH 7.5 CVE-2012-2227EPSS 10% Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via… Pluxml after 5.1.5 Fix from $1,9502012-08-26 MEDIUM 5.0 CVE-2012-4674 PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID. Pluxml after 5.1.5 Fix from $1,6002012-08-26 HIGH 7.5 CVE-2007-3432EPSS 8% Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jp… Pluxml No fix yet Fix from $1,9502007-06-27