Vulnerabilities > Pluck CMS > High

DATE CVE VULNERABILITY TITLE RISK
2023-12-14 CVE-2023-50564 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.18
An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file.
network
low complexity
pluck-cms CWE-434
8.8
2023-06-22 CVE-2023-27083 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.15/4.7.16
An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.
network
low complexity
pluck-cms CWE-434
7.2
2023-06-20 CVE-2020-20918 Code Injection vulnerability in Pluck-Cms Pluck 4.7.10
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
network
low complexity
pluck-cms CWE-94
7.2
2023-06-20 CVE-2020-20919 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.10
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
network
low complexity
pluck-cms CWE-434
7.2
2023-06-20 CVE-2020-20969 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.10
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
network
low complexity
pluck-cms CWE-434
7.2
2023-03-27 CVE-2023-25828 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck
Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module.
network
low complexity
pluck-cms CWE-434
7.2
2021-12-10 CVE-2021-27984 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.15
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
network
low complexity
pluck-cms CWE-434
7.5
2021-12-10 CVE-2021-31746 Path Traversal vulnerability in Pluck-Cms Pluck 4.7.15
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.
network
low complexity
pluck-cms CWE-22
7.5
2019-07-16 CVE-2019-1010062 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluckcms
PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type.
network
low complexity
pluck-cms CWE-434
7.5
2019-04-19 CVE-2019-11344 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.8
data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.
network
low complexity
pluck-cms CWE-434
7.5