Vulnerabilities
Vulnerable Software
Pluck-Cms:  >> Pluck  >> 4.7.18  Security Vulnerabilities
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
CVSS Score
9.8
EPSS Score
0.002
Published
2024-08-16
An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file.
CVSS Score
8.8
EPSS Score
0.191
Published
2023-12-14
A vulnerability has been found in Pluck CMS 4.7.18 and classified as problematic. This vulnerability affects unknown code of the file install.php of the component Installation Handler. The manipulation of the argument contents with the input <script>alert('xss')</script> leads to cross site scripting. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-239854 is the identifier assigned to this vulnerability.
CVSS Score
2.6
EPSS Score
0.001
Published
2023-09-16


Contact Us

Shodan ® - All rights reserved