Vulnerabilities (CVE)

Filtered by vendor Pluck-cms Subscribe
Filtered by product Pluck
Total 42 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11331 1 Pluck-cms 1 Pluck 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.
CVE-2018-11330 1 Pluck-cms 1 Pluck 2024-11-21 3.5 LOW 4.8 MEDIUM
An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted.