Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pluxml

First CVE: Jun 27, 2007Active for: 19 yearsTotal CVEs: 22
34.9
VTI Score
Medium

Pluxml is a lightweight, self-hosted blogging and content-management platform with a modest but notably represented presence in the vulnerability landscape, particularly among small publishers and personal websites. Its vulnerability footprint concentrates entirely on the core Pluxml application and recurs through a durable pattern of input-handling and code-execution weaknesses: cross-site scripting, code injection, untrusted deserialization, and information disclosure are the characteristic defects across its disclosures. A meaningful share of Pluxml's vulnerabilities reach serious severity, and the vendor's flaws have an elevated tendency to acquire public exploit code, reflecting both the maturity of web-application security tooling and the platform's open-source availability. Defenders managing or auditing instances of Pluxml should prioritize patching releases that address injection and serialization flaws; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pluxml over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2007
19 years ago
Most Recent CVE
Mar 10, 2026
136 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-2227HIGH
Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash
Aug 26, 20127.536NOYES
CVE-2026-24352CRITICAL
PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker
Feb 27, 20269.832NONO
CVE-2022-25018HIGH
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.
Mar 1, 20228.832NONO
CVE-2007-3432HIGH
Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg filename.
Jun 27, 20077.531NOYES
CVE-2020-18185CRITICAL
class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.
Oct 2, 20209.829NONO
CVE-2025-15438HIGH
A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the component Media Management Module
Jan 2, 20267.224NONO
CVE-2024-22636HIGH
PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payloa
Jan 25, 20248.824NONO
CVE-2022-25020MEDIUM
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.
Mar 1, 20225.423NONO
CVE-2025-67436MEDIUM
Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.p
Dec 22, 20256.522NONO
CVE-2025-70128MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize o
Mar 10, 20266.121NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
68%
23%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (77.3%)
Unknown5 (22.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (77.3%)
High0 (0.0%)
Unknown5 (22.7%)
User Interaction
None7 (31.8%)
Unknown5 (22.7%)
Required10 (45.5%)
Privileges Required
Low9 (40.9%)
High4 (18.2%)
None4 (18.2%)
Unknown5 (22.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
13.6% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pluxml.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pluxml — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pluxml's Products

View all 4 CNAs →

Top CWEs