Known Vulnerabilities for products from Pluck-cms
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Pluck-cms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-31205 json | Not Provided | 2026-05-04 | 2026-05-04 | |
| CVE-2026-16205 json | Not Provided | 2026-07-19 | 2026-07-20 | |
| CVE-2025-46099 json | In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory ... | Not Provided | 2025-07-23 | 2026-07-05 |
| CVE-2023-27083 json | An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via m... | 7.2 - HIGH | 2023-06-22 | 2023-11-07 |
| CVE-2023-27082 json | Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run... | 4.8 - MEDIUM | 2023-06-26 | 2023-11-07 |
| CVE-2023-25828 json | Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums... | 7.2 - HIGH | 2023-03-27 | 2023-11-07 |
| CVE-2023-5013 json | A vulnerability has been found in Pluck CMS 4.7.18 and classified as problematic. This vulnerability affects unknown code of ... | 5.4 - MEDIUM | 2023-09-16 | 2023-11-07 |
| CVE-2022-27432 json | A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploit... | 8.8 - HIGH | 2022-03-30 | 2022-04-05 |
| CVE-2022-26965 json | In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote cod... | 7.2 - HIGH | 2022-03-18 | 2022-03-25 |
| CVE-2022-26589 json | A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages. | 6.5 - MEDIUM | 2022-04-13 | 2023-11-07 |
| CVE-2021-31747 json | Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle a... | 4.8 - MEDIUM | 2021-12-10 | 2021-12-14 |
| CVE-2021-31746 json | Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in direc... | 9.8 - CRITICAL | 2021-12-10 | 2021-12-14 |
| CVE-2021-31745 json | Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to th... | 7.5 - HIGH | 2021-12-10 | 2021-12-14 |
| CVE-2021-27984 json | In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files. | 8.1 - HIGH | 2021-12-10 | 2021-12-14 |
| CVE-2020-29607 json | A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in t... | 7.2 - HIGH | 2020-12-16 | 2022-02-07 |
| CVE-2020-24740 json | An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpag... | 4.3 - MEDIUM | 2021-05-18 | 2021-05-24 |
| CVE-2020-21564 json | An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote com... | 8.8 - HIGH | 2020-09-30 | 2021-09-21 |
| CVE-2020-20969 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.2 - HIGH | 2023-06-20 | 2023-06-27 |
| CVE-2020-20951 json | In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files. | 9.8 - CRITICAL | 2021-05-18 | 2022-10-26 |
| CVE-2020-20919 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.2 - HIGH | 2023-06-20 | 2023-06-27 |