Show filters
35 Total Results
Displaying 11-20 of 35
Sort by:
Attacker Value
Unknown

CVE-2022-27432

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
Attacker Value
Unknown

CVE-2022-26965

Disclosure Date: March 18, 2022 (last updated February 23, 2025)
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.
Attacker Value
Unknown

CVE-2021-31747

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.
Attacker Value
Unknown

CVE-2021-27984

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
Attacker Value
Unknown

CVE-2021-31746

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.
Attacker Value
Unknown

CVE-2021-31745

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.
Attacker Value
Unknown

CVE-2020-24740

Disclosure Date: May 18, 2021 (last updated February 22, 2025)
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
Attacker Value
Unknown

CVE-2020-20951

Disclosure Date: May 18, 2021 (last updated February 22, 2025)
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
Attacker Value
Unknown

CVE-2020-18198

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component " /admin.php?action=images."
Attacker Value
Unknown

CVE-2020-18195

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page."