Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Pluxml CRITICAL 9.8
CVE-2026-24352

PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This…

Mitigation only
Fix from $2,300 2026-02-27
Pluxml MEDIUM 5.4
CVE-2026-24351

PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into …

Mitigation only
Fix from $1,600 2026-02-27
Pluxml MEDIUM 5.4
CVE-2026-24350

PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious paylo…

Mitigation only
Fix from $1,600 2026-02-27
Pluxml MEDIUM 6.5
CVE-2025-67436

Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell …

No fix yet
Fix from $1,600 2025-12-22
Pluxml HIGH 8.8
CVE-2024-22636

PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited…

No fix yet
Fix from $1,950 2024-01-25
Pluxml HIGH 8.8
CVE-2022-25018

Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

Mitigation only
Fix from $1,950 2022-03-01
Pluxml MEDIUM 5.4
CVE-2022-25020

A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the th…

No fix yet
Fix from $1,600 2022-03-01
Pluxml MEDIUM 5.4
CVE-2022-24585

A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbitrary web…

No fix yet
Fix from $1,600 2022-02-15
Pluxml MEDIUM 5.4
CVE-2022-24587

A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitrary web s…

No fix yet
Fix from $1,600 2022-02-15
Pluxml MEDIUM 5.4
CVE-2022-24586

A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary …

No fix yet
Fix from $1,600 2022-02-15
Pluxml CRITICAL 9.8
CVE-2020-18185

class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.

No fix yet
Fix from $2,300 2020-10-02
Pluxml MEDIUM 5.4
CVE-2017-1001001

PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of pr…

Mitigation only
Fix from $1,600 2017-11-01
Pluxml HIGH 7.5
CVE-2007-3432EPSS 8%

Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jp…

No fix yet
Fix from $1,950 2007-06-27