Products: 1
    Vulnerabilities: 24
    Known Exploited: 0
    4
    Critical Level Threats
    4
    High Level Threats
    16
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-70129

    If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be automatically recognized for articles, such that an automated script is able to solve this anti-spam mechanism trivially and publish spam comments. The details of captcha challenge are exposed within document body of articles with comments & anti spam-captcha functionalities enabled, including "capcha-letter", "capcha-word" and "capcha-token" which can be used to construct a valid post request to publish a comment. As such, attackers can flood articles with automated spam comments, especially if there are no other web defenses available.

    Last Modified: Apr 07, 2026
    Published: Mar 10, 2026

    CVE-2025-70128

    A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize or validate user-supplied input in the "link" field of a comment. An attacker can inject arbitrary JavaScript code using a <script> element. The injected payload is stored in the database and subsequently rendered in the Administration panel's "Comments" section when administrators review submitted comments. Importantly, the malicious script is not reflected in the public-facing comments interface, but only within the backend administration view. Alternatively, users of Administrator, Moderator, Manager roles can also directly input crafted payloads into existing comments. This makes the vulnerability a persistent XSS issue targeting administrative users. This affects /core/admin/comments.php, while CVE-2022-24585 affects /core/admin/comment.php, a uniquely distinct vulnerability.

    Last Modified: Apr 07, 2026
    Published: Mar 10, 2026

    CVE-2026-24352

    Session Fixation in PluXml CMS

    Last Modified: May 19, 2026
    Published: Feb 27, 2026

    CVE-2026-24351

    Stored XSS in PluXml CMS

    Last Modified: May 19, 2026
    Published: Feb 27, 2026

    CVE-2026-24350

    Stored XSS in PluXml CMS

    Last Modified: May 22, 2026
    Published: Feb 27, 2026
    Items Per Page