Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pligg

First CVE: Oct 18, 2007Active for: 19 yearsTotal CVEs: 45
45.7
VTI Score
High

Pligg is a content-management and social-networking platform whose vulnerability footprint, though concentrated in a narrow product line, sits among the more prominent vendors in the landscape. Vulnerabilities affecting Pligg skew toward meaningful serious outcomes and have acquired public exploit code at an elevated rate, reflecting both the platform's history as an open-source project and the appeal of its web-facing attack surface to security researchers. The exposure recurs consistently across the Pligg CMS product through web-layer weakness classes including cross-site request forgery, SQL injection, cross-site scripting, path traversal, and exposure of sensitive information—weaknesses endemic to content-management systems and particularly common in older or less-frequently-maintained codebases. Defenders deploying Pligg should prioritize input-handling and request-origin validation controls and treat this vendor's security advisories with urgency given the public-exploit tendency; live severity, exploitation, and current exposure counts are shown alongside this summary.

FAUCET AI Generated
45
Total CVEs
More Total CVEs than 98% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pligg over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2007
18 years ago
Most Recent CVE
Aug 20, 2024
703 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (45 CVEs).

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-7090HIGH
Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .. (dot dot) in the $tb_url var
Aug 26, 20097.834NOYES
CVE-2011-5022HIGH
SQL injection vulnerability in search.php in Pligg CMS 1.1.2 allows remote attackers to execute arbitrary SQL commands via the status parameter.
Dec 29, 20117.533NOYES
CVE-2022-34956CRITICAL
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_groups.php.
Aug 2, 20229.830NONO
CVE-2022-34955CRITICAL
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_topusers.php.
Aug 2, 20229.830NONO
CVE-2008-7091HIGH
Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to vote.php, which is not properly
Aug 26, 20097.530NOYES
CVE-2014-9096HIGH
Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) n parameter.
Nov 26, 20147.528NOYES
CVE-2008-6968HIGH
Multiple SQL injection vulnerabilities in submit.php in Pligg CMS 9.9.5 allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.
Aug 13, 20097.528NOYES
CVE-2008-5739HIGH
SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQL commands via the url parameter.
Dec 26, 20087.528NOYES
CVE-2008-3366HIGH
SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2008-
Jul 30, 20087.528NOYES
CVE-2008-1774HIGH
SQL injection vulnerability in editlink.php in Pligg 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Apr 14, 20087.528NOYES
View all 45 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products45 CVEs
29%
64%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (44.4%)
Unknown25 (55.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (44.4%)
High0 (0.0%)
Unknown25 (55.6%)
User Interaction
None4 (8.9%)
Unknown25 (55.6%)
Required16 (35.6%)
Privileges Required
Low0 (0.0%)
High1 (2.2%)
None19 (42.2%)
Unknown25 (55.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
14 CVEs
31.1% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pligg.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pligg — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pligg's Products

View all 2 CNAs →

Top CWEs