Exploit Database
153,440 exploits tracked across all sources.
HashBrown CMS <1.3.2 - Path Traversal
An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach a parent directory via a crafted name or ID field.
CVSS 7.5
Pluck CMS: CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and RCE
Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.
CVSS 9.6
Pluck CMS: Unrestricted File Upload via Missing .php8 Extension in Upload Blacklist
Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar'), checked against the last 4-5 characters of the filename.
CVSS 7.2
Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting
A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. Executing a manipulation of the argument Info can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 2.4
Pluck 4.7.8 - Remote Code Execution
data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.
CVSS 9.8
PluckCMS <4.7.4 - Unrestricted Upload of File with Dangerous Type
PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type. The impact is: get webshell. The component is: data/inc/images.php line36. The attack vector is: modify the MIME TYPE on HTTP request to upload a php file. The fixed version is: after commit 09f0ab871bf633973cfd9fc4fe59d4a912397cf8.
CVSS 9.8
Pluck < 4.7.4 - Unauthenticated Stored Cross-Site Scripting in Blog Reaction Comments
An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL.
CVSS 6.1
Pluck 4.7.7 - Stored Cross-Site Scripting via SVG File Upload
Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files.
CVSS 5.4
Pluck < 4.7.7-dev2 - Unauthenticated Arbitrary PHP File Upload via .htaccess MIME Type Bypass
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.
CVSS 9.8
Pluck < 4.7.7-dev2 - Unauthenticated Arbitrary PHP File Upload via .htaccess MIME Type Bypass
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.
CVSS 9.8
Pluck < 4.7.6 - Remote Code Execution via Unrestricted File Upload
An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.
CVSS 9.8
Pluck < 4.7.6 - Authenticated Stored Cross-Site Scripting via Filename
An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted.
CVSS 4.8
Pluck CMS < 4.7.13 - Authenticated Remote Code Execution via File Upload Restriction Bypass
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
CVSS 7.2
Pluck 4.7.10 - Remote Code Execution via Trashcan Restore Item File Upload
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
CVSS 7.2
Pluck CMS 4.7.10-dev2 - Unrestricted File Upload via theme.php
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
CVSS 7.2
Pluck CMS 4.7.10-dev2 - Remote Code Execution via Admin Page Edit Parameter
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
CVSS 7.2
PluckCMS 4.7.10 - Remote Code Execution via Crafted Image File Upload
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.
CVSS 9.8
Pluck 4.7.15 - Improper Certificate Validation in update_applet.php
Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.
CVSS 4.8
Pluck 4.7.15 - Path Traversal and Arbitrary Code Execution via Zip File Upload
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.
CVSS 9.8
Pluck-CMS Pluck <4.7.15 - Session Fixation
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.
CVSS 7.5
Pluck CMS 4.7.15 - Admin File Upload Command Execution
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
CVSS 8.1
Pluck 4.7.10-dev2 - Cross-Site Request Forgery via Edit Page Action
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
CVSS 4.3
Pluck CMS 4.7.10-dev2 and 4.7.11 - Remote Code Execution via File Upload
An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.
CVSS 8.8
Pluck CMS 4.7.10-dev2 and 4.7.11 - Remote Code Execution via File Upload
An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.
CVSS 8.8
Pluck 4.7.10-dev2 - Remote Command Execution via File Upload
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
CVSS 9.8
By Source