VendorsPluck-cmspluck4.7.10
Vulnerabilities

Pluck-cms Pluck 4.7.10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-20951
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
Published 2021-05-18 · Modified
9.8EPSS 0.040
CVE-2020-21564
An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.
Published 2020-09-30 · Modified
8.8EPSS 0.035
CVE-2020-20969
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
Published 2023-06-20 · Modified
7.21 PoCEPSS 0.062
CVE-2020-20919
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
Published 2023-06-20 · Modified
7.2EPSS 0.013
CVE-2020-20918
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
Published 2023-06-20 · Modified
7.2EPSS 0.011
CVE-2020-24740
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
Published 2021-05-18 · Modified
4.3EPSS 0.004