VendorsPluck-cmspluck4.7.18
Vulnerabilities

Pluck-cms Pluck 4.7.18

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-43042
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
Published 2024-08-16 · Modified
9.8EPSS 0.006
CVE-2023-50564
An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file.
Published 2023-12-14 · Modified
8.8EPSS 0.291
CVE-2023-5013
Pluck CMS Installation install.php cross site scripting
Published 2023-09-16 · Modified
5.4EPSS 0.006