Vulnerabilities > Pluck CMS > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-08-16 CVE-2024-43042 Improper Restriction of Excessive Authentication Attempts vulnerability in Pluck-Cms Pluck 4.7.18
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
network
low complexity
pluck-cms CWE-307
critical
9.8
2023-06-20 CVE-2020-20718 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluckcms 4.7.10
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.
network
low complexity
pluck-cms CWE-434
critical
9.8
2021-12-10 CVE-2021-31746 Path Traversal vulnerability in Pluck-Cms Pluck 4.7.15
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.
network
low complexity
pluck-cms CWE-22
critical
9.8
2021-05-18 CVE-2020-20951 Command Injection vulnerability in Pluck-Cms Pluck 4.7.10
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
network
low complexity
pluck-cms CWE-77
critical
9.8
2019-07-16 CVE-2019-1010062 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluckcms
PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type.
network
low complexity
pluck-cms CWE-434
critical
9.8
2019-04-19 CVE-2019-11344 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.8
data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.
network
low complexity
pluck-cms CWE-434
critical
9.8
2018-06-05 CVE-2018-11736 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck
An issue was discovered in Pluck before 4.7.7-dev2.
network
low complexity
pluck-cms CWE-434
critical
9.8
2018-05-21 CVE-2018-11331 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck
An issue was discovered in Pluck before 4.7.6.
network
low complexity
pluck-cms CWE-434
critical
9.8
2017-03-17 CVE-2014-8708 Permissions, Privileges, and Access Controls vulnerability in Pluck-Cms Pluck 4.7.2
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
network
low complexity
pluck-cms CWE-264
critical
9.8