Vulnerabilities (CVE)

Filtered by vendor Pluck-cms Subscribe
Filtered by product Pluck
Total 42 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-26965 1 Pluck-cms 1 Pluck 2024-02-28 6.5 MEDIUM 7.2 HIGH
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.
CVE-2022-26589 1 Pluck-cms 1 Pluck 2024-02-28 4.3 MEDIUM 6.5 MEDIUM
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.