« Volver al listado

Pluxml

Pluxml: vulnerabilidades y CVE

Pluxml tiene 23 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE23
Últimos 12 meses7
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-70129Media (5.3)0.29%—10 mar 2026
If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be automatically recognized for articles, such that an automated script is…
CVE-2025-70128Media (6.1)0.22%—10 mar 2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize or validate user-supplied input in the…
CVE-2026-24352Media (4.8)0.36%—27 feb 2026
PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and…
CVE-2026-24351Media (5.1)0.18%—27 feb 2026
PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page.…
CVE-2026-24350Media (5.1)0.17%—27 feb 2026
PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious payload, which will be executed when a victim clicks the link associated…
CVE-2025-15438Baja (2)0.47%—2 ene 2026
A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the component Media Management Module. Executing a manipulation of the…
CVE-2025-67436Media (6.5)0.59%—22 dic 2025
Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.php).
CVE-2024-48138Crítica (9.8)0.86%—29 oct 2024
A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted payload into a…
CVE-2024-22636Alta (8.8)1.3%—25 ene 2024
PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payload into the Content field.
CVE-2022-25020Media (5.4)1.2%—1 mar 2022
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.
CVE-2022-25018Alta (8.8)2.7%—1 mar 2022
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.
CVE-2022-24587Media (5.4)0.74%—15 feb 2022
A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML.
CVE-2022-24585Media (5.4)0.75%—15 feb 2022
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the author parameter.
CVE-2022-24586Media (5.4)0.75%—15 feb 2022
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content and thumbnail…
CVE-2021-38603Media (4.8)1.1%—12 ago 2021
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.
CVE-2021-38602Media (4.8)0.76%—12 ago 2021
PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.
CVE-2020-18185Crítica (9.8)1.8%—2 oct 2020
class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.
CVE-2017-1001001Media (5.4)0.64%—1 nov 2017
PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges.
CVE-2012-4675Media (4.3)1.2%—26 ago 2012
Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to file update.
CVE-2012-4674Media (5)1.2%—26 ago 2012
PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.
CVE-2012-2227Alta (7.5)9.8%—26 ago 2012
Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the default_lang parameter.
CVE-2007-3542Media (4.3)1.9%—3 jul 2007
Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
CVE-2007-3432Alta (7.5)8.2%—27 jun 2007
Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg filename.

Otros productos de Pluxml