Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Moderate

CVE-2021-38603

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.
Attacker Value
Unknown

CVE-2024-22636

Disclosure Date: January 25, 2024 (last updated January 30, 2024)
PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payload into the Content field.
Attacker Value
Unknown

CVE-2022-25020

Disclosure Date: March 01, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.
Attacker Value
Unknown

CVE-2022-25018

Disclosure Date: March 01, 2022 (last updated February 23, 2025)
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.
Attacker Value
Unknown

CVE-2022-24587

Disclosure Date: February 15, 2022 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML.
Attacker Value
Unknown

CVE-2022-24585

Disclosure Date: February 15, 2022 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the author parameter.
Attacker Value
Unknown

CVE-2022-24586

Disclosure Date: February 15, 2022 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content and thumbnail parameters.
Attacker Value
Unknown

CVE-2021-38602

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.
Attacker Value
Unknown

CVE-2020-18185

Disclosure Date: October 02, 2020 (last updated February 22, 2025)
class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.
Attacker Value
Unknown

CVE-2017-1001001

Disclosure Date: November 01, 2017 (last updated November 08, 2023)
PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges.
0