« Volver al listado

Pluck

Pluck CMS: vulnerabilidades y CVE

Pluck CMS tiene 5 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses4
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-70376Crítica (9.6)0.20%—5 ago 2026
Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token…
CVE-2026-54416Alta (7.2)0.50%—5 ago 2026
Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php…
CVE-2026-16205Baja (1.9)0.35%—19 jul 2026
A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. Executing a…
CVE-2026-31205Media (5.7)0.47%—4 may 2026
Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanitizePageContent function
CVE-2024-9405Media (5.3)0.46%—1 oct 2024
An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1185 Browser Session Hijacking1
  2. T1203 Exploitation for Client Execution1
  3. T1210 Exploitation of Remote Services1
  4. T1505.003 Web Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Pluck