Filtered by vendor Pluck-cms
Subscribe
Total
44 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-6253 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the g_pcltar_lib_dir parameter. | |||||
CVE-2023-50564 | 1 Pluck-cms | 1 Pluck | 2024-10-08 | N/A | 8.8 HIGH |
An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file. | |||||
CVE-2024-43042 | 1 Pluck-cms | 1 Pluck | 2024-09-19 | N/A | 9.8 CRITICAL |
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack. | |||||
CVE-2023-5013 | 1 Pluck-cms | 1 Pluck | 2024-05-17 | 2.1 LOW | 5.4 MEDIUM |
A vulnerability has been found in Pluck CMS 4.7.18 and classified as problematic. This vulnerability affects unknown code of the file install.php of the component Installation Handler. The manipulation of the argument contents with the input <script>alert('xss')</script> leads to cross site scripting. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-239854 is the identifier assigned to this vulnerability. |