VendorsPluck-cmspluckall versions
Vulnerabilities

Pluck-cms Pluck

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2018-11330
An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted.
Published 2018-05-21 · Modified
4.8EPSS 0.007
CVE-2023-27082
Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file.
Published 2023-06-26 · Modified
4.8EPSS 0.006
CVE-2020-24740
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
Published 2021-05-18 · Modified
4.3EPSS 0.004
← Prev2 / 2