Vulnerabilities > Pluck CMS > Pluck > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-09-16 | CVE-2023-5013 | Cross-site Scripting vulnerability in Pluck-Cms Pluck 4.7.18 A vulnerability has been found in Pluck CMS 4.7.18 and classified as problematic. | 5.4 |
2023-06-26 | CVE-2023-27082 | Cross-site Scripting vulnerability in Pluck-Cms Pluck 4.7.15/4.7.16 Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file. | 4.8 |
2022-04-13 | CVE-2022-26589 | Cross-Site Request Forgery (CSRF) vulnerability in Pluck-Cms Pluck 4.7.15 A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages. | 6.5 |
2021-12-10 | CVE-2021-31747 | Improper Certificate Validation vulnerability in Pluck-Cms Pluck 4.7.15 Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks. | 4.8 |
2021-05-18 | CVE-2020-24740 | Cross-Site Request Forgery (CSRF) vulnerability in Pluck-Cms Pluck 4.7.10 An issue was discovered in Pluck 4.7.10-dev2. | 4.3 |
2019-02-23 | CVE-2019-9052 | Cross-Site Request Forgery (CSRF) vulnerability in Pluck-Cms Pluck 4.7.9 An issue was discovered in Pluck 4.7.9-dev1. | 6.5 |
2019-02-23 | CVE-2019-9051 | Cross-Site Request Forgery (CSRF) vulnerability in Pluck-Cms Pluck 4.7.9 An issue was discovered in Pluck 4.7.9-dev1. | 6.5 |
2019-02-23 | CVE-2019-9049 | Cross-Site Request Forgery (CSRF) vulnerability in Pluck-Cms Pluck 4.7.9 An issue was discovered in Pluck 4.7.9-dev1. | 6.5 |
2019-02-23 | CVE-2019-9048 | Cross-Site Request Forgery (CSRF) vulnerability in Pluck-Cms Pluck 4.7.9 An issue was discovered in Pluck 4.7.9-dev1. | 6.5 |
2018-12-04 | CVE-2018-16633 | Cross-site Scripting vulnerability in Pluck-Cms Pluck 4.7.7 Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title. | 5.4 |