Pluck-cms

Pluckcms

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 05.08.2026 06:58:44
  • Zuletzt bearbeitet 10.08.2026 12:17:23

Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.

  • EPSS 0.34%
  • Veröffentlicht 05.08.2026 06:58:23
  • Zuletzt bearbeitet 10.08.2026 12:17:17

Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar')...

  • EPSS 0.28%
  • Veröffentlicht 04.05.2026 14:16:32
  • Zuletzt bearbeitet 05.05.2026 19:44:42

Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanitizePageContent function

  • EPSS 0.46%
  • Veröffentlicht 23.07.2025 00:00:00
  • Zuletzt bearbeitet 05.07.2026 01:21:47

In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET paramet...

  • EPSS 0.46%
  • Veröffentlicht 01.10.2024 12:15:03
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file loc...

Exploit
  • EPSS 1.31%
  • Veröffentlicht 20.06.2023 15:15:10
  • Zuletzt bearbeitet 10.12.2024 18:15:22

File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.

  • EPSS 1.81%
  • Veröffentlicht 16.07.2019 13:15:11
  • Zuletzt bearbeitet 21.11.2024 04:17:57

PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type. The impact is: get webshell. The component is: data/inc/images.php line36. The attack vector is: modify the MIME TYPE on HTTP request to upload a php ...