CVE-2023-27082: Pluck-CMS Pluck
Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file.
Affected products
- Pluck-CMS Pluck: from 4.7.15, before 4.7.16 (fixed in 4.7.16); version 4.7.16 only
Published 2023-06-26. Last modified 2026-06-17.