Vulnerabilities > Pluck CMS > Pluck > 4.7.2

DATE CVE VULNERABILITY TITLE RISK
2023-03-27 CVE-2023-25828 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck
Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module.
network
low complexity
pluck-cms CWE-434
7.2
2020-12-16 CVE-2020-29607 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
network
low complexity
pluck-cms CWE-434
6.5
2018-06-05 CVE-2018-11736 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck
An issue was discovered in Pluck before 4.7.7-dev2.
network
low complexity
pluck-cms CWE-434
7.5
2018-05-21 CVE-2018-11331 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck
An issue was discovered in Pluck before 4.7.6.
network
low complexity
pluck-cms CWE-434
7.5
2018-05-21 CVE-2018-11330 Cross-site Scripting vulnerability in Pluck-Cms Pluck
An issue was discovered in Pluck before 4.7.6.
network
pluck-cms CWE-79
3.5
2018-02-18 CVE-2018-7197 Cross-site Scripting vulnerability in Pluck-Cms Pluck
An issue was discovered in Pluck through 4.7.4.
network
pluck-cms CWE-79
4.3
2017-03-17 CVE-2014-8708 Permissions, Privileges, and Access Controls vulnerability in Pluck-Cms Pluck 4.7.2
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
network
low complexity
pluck-cms CWE-264
7.5
2017-03-17 CVE-2014-8707 Cross-site Scripting vulnerability in Pluck-Cms Pluck 4.7.2
Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbitrary web script or HTML via the "edit HTML source" option.
network
low complexity
pluck-cms CWE-79
4.0
2017-03-17 CVE-2014-8706 Information Exposure vulnerability in Pluck-Cms Pluck 4.7.2
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to an array; or (4) changing the image parameter to a string, which reveals the installation path in an error message.
network
low complexity
pluck-cms CWE-200
5.0