Product:

Pligg_cms

(Pligg)
Repositories https://github.com/Pligg/pligg-cms
#Vulnerabilities 41
Date Id Summary Products Score Patch Annotated
2024-08-20 CVE-2024-42610 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files Pligg_cms 8.8
2024-08-20 CVE-2024-42611 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete Pligg_cms 8.8
2024-08-20 CVE-2024-42613 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akismet Pligg_cms 8.8
2024-08-20 CVE-2024-42616 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=remove&widget=Statistics Pligg_cms 8.8
2024-08-20 CVE-2024-42617 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php?action=save&var_id=32 Pligg_cms 8.8
2024-08-20 CVE-2024-42618 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karma Pligg_cms 8.8
2024-08-20 CVE-2024-42621 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php Pligg_cms 8.8
2011-12-29 CVE-2011-5022 SQL injection vulnerability in search.php in Pligg CMS 1.1.2 allows remote attackers to execute arbitrary SQL commands via the status parameter. Pligg_cms N/A
2011-12-29 CVE-2011-5023 Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the search program, a different vulnerability than CVE-2011-3986. Pligg_cms N/A
2015-08-31 CVE-2015-6655 Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php. Pligg_cms N/A