VendorsPluck-cmspluckany version
Vulnerabilities

Pluck-cms Pluck any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2018-11736
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.
Published 2018-06-05 · Modified
9.81 PoCEPSS 0.086
CVE-2018-11331
An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.
Published 2018-05-21 · Modified
9.8EPSS 0.023
CVE-2020-29607
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
Published 2020-12-16 · Modified
7.21 PoCEPSS 0.332
CVE-2023-25828
Authenticate Remote Code Execution in Pluck CMS
Published 2023-03-27 · Modified
7.2EPSS 0.016
CVE-2023-27083
An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.
Published 2023-06-22 · Modified
7.2EPSS 0.012
CVE-2018-7197
An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL.
Published 2018-02-18 · Modified
6.1EPSS 0.014
CVE-2018-11330
An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted.
Published 2018-05-21 · Modified
4.8EPSS 0.007
CVE-2023-27082
Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file.
Published 2023-06-26 · Modified
4.8EPSS 0.006