Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-46099

In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.6%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2025-46099
  • Pluck-Cms » Pluck » Version: 4.7.20
    cpe:2.3:a:pluck-cms:pluck:4.7.20


Contact Us

Shodan ® - All rights reserved