Pluck-cms

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 49
    Known Exploited: 0
    10
    Critical Level Threats
    18
    High Level Threats
    20
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-70376

    Pluck CMS - CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and RCE

    Last Modified: Aug 10, 2026
    Published: Aug 05, 2026

    CVE-2026-54416

    Pluck CMS - Unrestricted File Upload via Missing .php8 Extension in Upload Blacklist

    Last Modified: Aug 10, 2026
    Published: Aug 05, 2026

    CVE-2026-31205

    Stored XSS in Pluck CMS Page Editor Enabling Privilege Escalation

    Last Modified: May 04, 2026
    Published: May 04, 2026

    CVE-2025-46099

    In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.

    Last Modified: Oct 14, 2025
    Published: Jul 23, 2025

    CVE-2024-9405

    An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or subdirectory as the module, but not from recursive directories.

    Last Modified: Apr 15, 2026
    Published: Oct 01, 2024
    Items Per Page