Pluxml is a lightweight, self-hosted blogging and content-management platform with a modest but notably represented presence in the vulnerability landscape, particularly among small publishers and personal websites. Its vulnerability footprint concentrates entirely on the core Pluxml application and recurs through a durable pattern of input-handling and code-execution weaknesses: cross-site scripting, code injection, untrusted deserialization, and information disclosure are the characteristic defects across its disclosures. A meaningful share of Pluxml's vulnerabilities reach serious severity, and the vendor's flaws have an elevated tendency to acquire public exploit code, reflecting both the maturity of web-application security tooling and the platform's open-source availability. Defenders managing or auditing instances of Pluxml should prioritize patching releases that address injection and serialization flaws; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pluxml over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2227HIGH Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash | Aug 26, 2012 | 7.5 | 36 | NO | YES |
CVE-2026-24352CRITICAL PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker | Feb 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2022-25018HIGH Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages. | Mar 1, 2022 | 8.8 | 32 | NO | NO |
CVE-2007-3432HIGH Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg filename. | Jun 27, 2007 | 7.5 | 31 | NO | YES |
CVE-2020-18185CRITICAL class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment. | Oct 2, 2020 | 9.8 | 29 | NO | NO |
CVE-2025-15438HIGH A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the component Media Management Module | Jan 2, 2026 | 7.2 | 24 | NO | NO |
CVE-2024-22636HIGH PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payloa | Jan 25, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-25020MEDIUM A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post. | Mar 1, 2022 | 5.4 | 23 | NO | NO |
CVE-2025-67436MEDIUM Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.p | Dec 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-70128MEDIUM A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize o | Mar 10, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pluxml.
Media articles that mention a CVE ID that affects a product developed by Pluxml — matched by CVE ID, not by vendor name.