Pligg
Pligg CMS: vulnerabilidades y CVE
Pligg CMS tiene 43 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE43
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-42619 | Alta (8.8) | 0.26% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?id=0&list=whitelist&remove=pligg.com |
| CVE-2024-42612 | Alta (8.8) | 0.29% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add |
| CVE-2024-42621 | Alta (8.8) | 0.29% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php |
| CVE-2024-42618 | Alta (8.8) | 0.29% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karma |
| CVE-2024-42617 | Alta (8.8) | 0.29% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php?action=save&var_id=32 |
| CVE-2024-42616 | Alta (8.8) | 0.29% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=remove&widget=Statistics |
| CVE-2024-42613 | Alta (8.8) | 0.29% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akismet |
| CVE-2024-42611 | Alta (8.8) | 0.29% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete |
| CVE-2024-42610 | Alta (8.8) | 0.29% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files |
| CVE-2024-42609 | Alta (8.8) | 0.22% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars |
| CVE-2024-42607 | Alta (8.8) | 0.29% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database |
| CVE-2024-42606 | Alta (8.8) | 0.21% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1 |
| CVE-2024-42605 | Alta (8.8) | 0.22% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1 |
| CVE-2024-42604 | Alta (8.8) | 0.29% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?mode=delete&group_id=3 |
| CVE-2024-42603 | Alta (8.8) | 0.21% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall |
| CVE-2024-42608 | Alta (8.8) | 0.29% | — | 20 ago 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php. |
| CVE-2023-37677 | Crítica (9.8) | 1.3% | — | 25 jul 2023 | Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php. |
| CVE-2022-34956 | Crítica (9.8) | 0.92% | — | 2 ago 2022 | Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_groups.php. |
| CVE-2022-34955 | Crítica (9.8) | 0.92% | — | 2 ago 2022 | Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_topusers.php. |
| CVE-2015-6655 | Media (6.8) | 2.0% | — | 31 ago 2015 | Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php. |
| CVE-2014-9096 | Alta (7.5) | 2.4% | — | 26 nov 2014 | Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) n parameter. |
| CVE-2012-2937 | Alta (7.5) | 2.4% | — | 27 may 2012 | Multiple SQL injection vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) list parameter in a move action to admin/admin_index.php, (2) display parameter in a… |
| CVE-2012-2936 | Media (4.3) | 1.3% | — | 27 may 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) page parameter to (a) admin/admin_comments.php or (b)… |
| CVE-2012-2436 | Media (4.3) | 2.5% | — | 27 may 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter in a move or (2) minimize action to… |
| CVE-2012-2435 | Media (6.5) | 1.6% | — | 27 may 2012 | Directory traversal vulnerability in the captcha module in Pligg CMS before 1.2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the captcha parameter to module.php,… |
| CVE-2011-5023 | Media (4.3) | 1.5% | — | 29 dic 2011 | Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the search program, a different vulnerability than CVE-2011-3986. |
| CVE-2011-5022 | Alta (7.5) | 0.93% | — | 29 dic 2011 | SQL injection vulnerability in search.php in Pligg CMS 1.1.2 allows remote attackers to execute arbitrary SQL commands via the status parameter. |
| CVE-2011-3986 | Media (4.3) | 1.3% | — | 3 nov 2011 | Cross-site scripting (XSS) vulnerability in Pligg before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2011-3794 | Media (5) | 1.2% | — | 24 sept 2011 | Pligg CMS 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/statistics/init.php and… |
| CVE-2010-3013 | Alta (7.5) | 1.3% | — | 16 ago 2010 | SQL injection vulnerability in groupadmin.php in Pligg before 1.1.1 allows remote attackers to execute arbitrary SQL commands via the role parameter, a different vulnerability than CVE-2010-2577. |