Known Vulnerabilities for products from Plume-cms
Listed below are 10 of the newest known vulnerabilities associated with the vendor "Plume-cms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2012-2156 json | Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4 and earlier allow remote attackers to inject arbitrary... | Not Provided | 2012-04-11 | 2026-04-29 |
| CVE-2012-1414 json | Cross-site request forgery (CSRF) vulnerability in manager/news.php in Plume CMS 1.2.4 and earlier allows remote attackers to... | Not Provided | 2012-10-07 | 2026-04-29 |
| CVE-2011-3985 json | Cross-site scripting (XSS) vulnerability in Plume before 1.2.3 allows remote attackers to inject arbitrary web script or HTML... | Not Provided | 2011-11-09 | 2026-04-29 |
| CVE-2009-3418 json | Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL comma... | Not Provided | 2009-09-25 | 2026-04-23 |
| CVE-2008-1048 json | Cross-site scripting (XSS) vulnerability in manager/xmedia.php in Plume CMS 1.2.2 allows remote attackers to inject arbitrary... | Not Provided | 2008-02-27 | 2026-04-23 |
| CVE-2006-7021 json | PHP remote file inclusion vulnerability in manager/tools/link/dbinstall.php in Plume CMS 1.1.3 allows remote attackers to exe... | Not Provided | 2007-02-15 | 2026-04-23 |
| CVE-2006-4533 json | Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 and earlier allow remote attackers to execute arbitrary... | 7.5 - HIGH | 2006-09-01 | 2011-11-10 |
| CVE-2006-3562 json | PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a URL i... | 7.5 - HIGH | 2006-07-13 | 2018-10-18 |
| CVE-2006-2645 json | PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execute ar... | 7.5 - HIGH | 2006-05-30 | 2018-10-18 |
| CVE-2006-0725 json | PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote at... | Not Provided | 2006-02-16 | 2025-04-03 |
Known software with vulnerabilities from Plume-cms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Plume-cms | Plume Cms | 1.0.2 |