Known Vulnerabilities for Pluck CMS by Pluck-cms
Listed below are 4 of the newest known vulnerabilities associated with "Pluck CMS" by "Pluck-cms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-70376 json | Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain() in data/inc/functions.admin.... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-54416 json | Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in dat... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-16205 json | A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of ... | Not Provided | 2026-07-19 | 2026-07-20 |
| CVE-2025-46099 json | In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory ... | Not Provided | 2025-07-23 | 2026-07-05 |