CVE-2018-19415: Plikli CMS

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to join_group.php or (2) comment_id parameter to story.php.

Affected products

  • Plikli Plikli CMS: version 4.0.0 only

Published 2019-01-03. Last modified 2026-06-17.