Plume CMS is a niche content management system with a modest vulnerability footprint concentrated in its single product offering. The vendor's disclosures reflect the typical input-handling and access-control surface area of a web-based publishing platform. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plume Cms over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1414MEDIUM Cross-site request forgery (CSRF) vulnerability in manager/news.php in Plume CMS 1.2.4 and earlier allows remote attackers to hijack the authentication of administrators for reques | Oct 7, 2012 | 6.8 | 30 | NO | YES |
CVE-2006-2645HIGH PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execute arbitrary code via a URL in the _PX_config[manager_path] | May 30, 2006 | 7.5 | 30 | NO | YES |
CVE-2006-7021HIGH PHP remote file inclusion vulnerability in manager/tools/link/dbinstall.php in Plume CMS 1.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the _PX_config[man | Feb 15, 2007 | 7.5 | 29 | NO | YES |
CVE-2006-3562HIGH PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter to (1) index.p | Jul 13, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-0725MEDIUM PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the _PX | Feb 16, 2006 | 6.8 | 27 | NO | YES |
CVE-2012-2156MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the u_email parameter (aka | Apr 11, 2012 | 4.3 | 25 | NO | YES |
CVE-2009-3418MEDIUM Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL commands via the m parameter to manager/index.php and (2) re | Sep 25, 2009 | 6.5 | 25 | NO | YES |
CVE-2006-4533HIGH Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 and earlier allow remote attackers to execute arbitrary PHP code via the _PX_config[manager_path] parameter to | Sep 1, 2006 | 7.5 | 20 | NO | NO |
CVE-2008-1048MEDIUM Cross-site scripting (XSS) vulnerability in manager/xmedia.php in Plume CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. | Feb 27, 2008 | 4.3 | 18 | NO | NO |
Cross-site scripting (XSS) vulnerability in Plume before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Nov 9, 2011 | 2.6 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plume Cms.
Media articles that mention a CVE ID that affects a product developed by Plume Cms — matched by CVE ID, not by vendor name.