CVE-2020-25287: Pligg Project Pligg
High severity, CVSS 7.2. EPSS: 2.7% chance of exploitation in the next 30 days.
Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any file, as demonstrated by an admin/admin_editor.php the_file=..%2Findex.php&open=Open request.
Affected products
- Pligg Project Pligg: version 2.0.3 only
Published 2020-09-13. Last modified 2026-06-17.