Vulnerabilities
Vulnerable Software
Plenti:  >> Plenti  >> 0.1.5  Security Vulnerabilities
Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.
CVSS Score
8.8
EPSS Score
0.009
Published
2025-03-12
Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote Code Execution. Version 0.7.2 fixes the vulnerability.
CVSS Score
7.5
EPSS Score
0.643
Published
2024-10-25
Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write deletion when a plenti user serves their website. This issue may lead to information loss. Version 0.7.2 fixes the vulnerability.
CVSS Score
7.5
EPSS Score
0.004
Published
2024-10-25


Contact Us

Shodan ® - All rights reserved