Vulnerabilities > Pluxml > High

DATE CVE VULNERABILITY TITLE RISK
2024-01-25 CVE-2024-22636 Unspecified vulnerability in Pluxml 5.8.9
PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature.
network
low complexity
pluxml
8.8
2020-10-02 CVE-2020-18185 Code Injection vulnerability in Pluxml 5.7
class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.
network
low complexity
pluxml CWE-94
7.5
2012-08-26 CVE-2012-2227 Path Traversal vulnerability in Pluxml 0.3.1/5.1.5
Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the default_lang parameter.
network
low complexity
pluxml CWE-22
7.5
2007-06-27 CVE-2007-3432 File-Upload vulnerability in Pluxml 0.3.1
Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg filename.
network
low complexity
pluxml
7.5