VendorsPluck-cmspluck4.7.15
Vulnerabilities

Pluck-cms Pluck 4.7.15

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2021-31746
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.
Published 2021-12-10 · Modified
9.8EPSS 0.024
CVE-2022-27432
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
Published 2022-03-29 · Modified
8.8EPSS 0.006
CVE-2021-27984
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
Published 2021-12-10 · Modified
8.1EPSS 0.025
CVE-2021-31745
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.
Published 2021-12-10 · Modified
7.5EPSS 0.012
CVE-2022-26589
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.
Published 2022-04-12 · Modified
6.5EPSS 0.005
CVE-2021-31747
Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.
Published 2021-12-10 · Modified
5.8EPSS 0.003