VendorsPluck-cmspluck4.7.8
Vulnerabilities

Pluck-cms Pluck 4.7.8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2019-11344
data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.
Published 2019-04-19 · Modified
9.8EPSS 0.036