Vulnerabilities > Pluxml > Pluxml > 5.8.7

DATE CVE VULNERABILITY TITLE RISK
2022-03-01 CVE-2022-25018 Code Injection vulnerability in Pluxml 5.8.7
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.
network
low complexity
pluxml CWE-94
6.5
2022-03-01 CVE-2022-25020 Cross-site Scripting vulnerability in Pluxml 5.8.7
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.
network
pluxml CWE-79
3.5
2022-02-15 CVE-2022-24585 Cross-site Scripting vulnerability in Pluxml 5.8.7
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the author parameter.
network
pluxml CWE-79
3.5
2022-02-15 CVE-2022-24587 Cross-site Scripting vulnerability in Pluxml 5.8.7
A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML.
network
pluxml CWE-79
3.5
2022-02-15 CVE-2022-24586 Cross-site Scripting vulnerability in Pluxml 5.8.7
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content and thumbnail parameters.
network
pluxml CWE-79
3.5
2021-08-12 CVE-2021-38602 Cross-site Scripting vulnerability in Pluxml 5.8.7
PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.
network
pluxml CWE-79
3.5
2021-08-12 CVE-2021-38603 Cross-site Scripting vulnerability in Pluxml 5.8.7
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.
network
pluxml CWE-79
3.5