Show filters
45 Total Results
Displaying 11-20 of 45
Sort by:
Attacker Value
Unknown

CVE-2023-25828

Disclosure Date: March 27, 2023 (last updated November 08, 2023)
Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which undergo a normalization process before being available on the site. Due to lack of file extension validation, it is possible to upload a crafted JPEG payload containing an embedded PHP web-shell. An attacker may navigate to it directly to achieve RCE on the underlying web server. Administrator credentials for the Pluck CMS web interface are required to access the albums module feature, and are thus required to exploit this vulnerability. CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C (8.2 High)
Attacker Value
Unknown

CVE-2022-26589

Disclosure Date: April 13, 2022 (last updated October 07, 2023)
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.
Attacker Value
Unknown

CVE-2022-27432

Disclosure Date: March 30, 2022 (last updated October 07, 2023)
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
Attacker Value
Unknown

CVE-2022-26965

Disclosure Date: March 18, 2022 (last updated October 07, 2023)
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.
Attacker Value
Unknown

CVE-2021-31747

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.
Attacker Value
Unknown

CVE-2021-27984

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
Attacker Value
Unknown

CVE-2021-31746

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.
Attacker Value
Unknown

CVE-2021-31745

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.
Attacker Value
Unknown

CVE-2020-24740

Disclosure Date: May 18, 2021 (last updated February 22, 2025)
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
Attacker Value
Unknown

CVE-2020-20951

Disclosure Date: May 18, 2021 (last updated February 22, 2025)
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.