Vulnerabilities > Pluxml > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-03-01 CVE-2022-25018 Code Injection vulnerability in Pluxml 5.8.7
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.
network
low complexity
pluxml CWE-94
6.5
2017-11-01 CVE-2017-1001001 Cross-site Scripting vulnerability in Pluxml 5.6
PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges.
network
low complexity
pluxml CWE-79
5.4
2012-08-26 CVE-2012-4675 Cross-Site Scripting vulnerability in Pluxml 0.3.1/5.1.5
Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to file update.
network
pluxml CWE-79
4.3
2012-08-26 CVE-2012-4674 Information Exposure vulnerability in Pluxml 0.3.1/5.1.5
PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.
network
low complexity
pluxml CWE-200
5.0
2007-07-03 CVE-2007-3542 Cross-Site Scripting vulnerability in Pluxml 0.3.1
Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
network
pluxml
4.3