Pluck CMS is a lightweight, self-hosted content management system that serves as an alternative to larger enterprise platforms, maintaining a narrow but durable vulnerability footprint concentrated in its core product. The vendor's disclosures span a modest volume of CVEs, with the recurring exposure tied to the application-layer architecture and content-handling mechanisms inherent to web-based CMS platforms. Defenders deploying Pluck CMS should prioritize inventory and patch-management discipline for self-hosted instances, as the vendor's update cadence and support model determine remediation timelines; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pluck Cms over time
Signals from CVEs in this vendor scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-29607HIGH A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which | Dec 16, 2020 | 7.2 | 55 | NO | YES |
CVE-2022-26965HIGH In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution. | Mar 18, 2022 | 7.2 | 47 | NO | YES |
CVE-2018-11736CRITICAL An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a | Jun 5, 2018 | 9.8 | 43 | NO | YES |
CVE-2023-50564HIGH An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file. | Dec 14, 2023 | 8.8 | 37 | NO | NO |
CVE-2009-1765MEDIUM Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot | May 22, 2009 | 6.8 | 33 | NO | YES |
CVE-2020-20969HIGH File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file. | Jun 20, 2023 | 7.2 | 32 | NO | YES |
CVE-2014-8708CRITICAL Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature. | Mar 17, 2017 | 9.8 | 32 | NO | NO |
CVE-2019-11344CRITICAL data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because onl | Apr 19, 2019 | 9.8 | 31 | NO | NO |
CVE-2008-6253MEDIUM Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local fi | Feb 24, 2009 | 6.8 | 31 | NO | YES |
CVE-2020-20718CRITICAL File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter. | Jun 20, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (45 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pluck Cms.
Media articles that mention a CVE ID that affects a product developed by Pluck Cms — matched by CVE ID, not by vendor name.