CVE-2020-20951: Pluck-CMS Pluck

Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.

In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.

Affected products

Published 2021-05-18. Last modified 2026-06-17.