CVE-2023-27083

HIGH

Pluck CMS <4.7.16-dev5 - RCE

Title source: llm
STIX 2.1

Description

An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.

Scores

CVSS v3 7.2
EPSS 0.0059
EPSS Percentile 69.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
pluck-cms/pluck 4.7.16 (6 CPE variants)
pluck-cms/pluck 4.7.15 - 4.7.16
Published Jun 22, 2023
Tracked Since Feb 18, 2026