CVE-2014-8707: Pluck-CMS Pluck

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbitrary web script or HTML via the "edit HTML source" option.

Affected products

Published 2017-03-17. Last modified 2026-06-17.