Vulnerabilities > Pluck CMS > High

DATE CVE VULNERABILITY TITLE RISK
2023-12-14 CVE-2023-50564 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.18
An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file.
network
low complexity
pluck-cms CWE-434
8.8
2023-06-22 CVE-2023-27083 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.15/4.7.16
An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.
network
low complexity
pluck-cms CWE-434
7.2
2023-06-20 CVE-2020-20918 Code Injection vulnerability in Pluck-Cms Pluck 4.7.10
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
network
low complexity
pluck-cms CWE-94
7.2
2023-06-20 CVE-2020-20919 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.10
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
network
low complexity
pluck-cms CWE-434
7.2
2023-06-20 CVE-2020-20969 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.10
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
network
low complexity
pluck-cms CWE-434
7.2
2023-03-27 CVE-2023-25828 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck
Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module.
network
low complexity
pluck-cms CWE-434
7.2
2022-03-30 CVE-2022-27432 Cross-Site Request Forgery (CSRF) vulnerability in Pluck-Cms Pluck 4.7.15
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
network
low complexity
pluck-cms CWE-352
8.8
2022-03-18 CVE-2022-26965 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.16
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.
network
low complexity
pluck-cms CWE-434
7.2
2021-12-10 CVE-2021-27984 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.15
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
network
high complexity
pluck-cms CWE-434
8.1
2021-12-10 CVE-2021-31745 Session Fixation vulnerability in Pluck-Cms Pluck 4.7.15
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform.
network
low complexity
pluck-cms CWE-384
7.5