PatchSiren

pluck-cms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL pluck-cms CVE published 2026-08-05

CVE-2026-70376

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T08:16:41.703Z and has not been modified since then. The vulnerability affects Pluck CMS installations, specifically the admin panel's reliance on a Referer-header comparison for CSRF protection, which can be bypassed by suppressing the Referer header, potentially leading to stored XSS and remote [truncated]

HIGH pluck-cms CVE published 2026-08-05

CVE-2026-54416

CVE-2026-54416 is a HIGH severity vulnerability in Pluck CMS 4.7.21, allowing an authenticated administrator to upload a file with a '.php8' extension, which can be executed as PHP code on servers running PHP 8.x, leading to remote code execution. The vulnerability exists due to a blacklist in data/inc/files.php that omits the '.php8' extension. This issue has a CVSS score of 7.2 and is rated HIGH. Admini [truncated]

LOW pluck-cms CVE published 2026-07-19

CVE-2026-16205

A weakness has been identified in Pluck CMS up to 4.7.21, affecting the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. This vulnerability can lead to cross-site scripting. The CVE record was published on 2026-07-19T03:16:42.250Z and has not been modified since then. Users of Pluck CMS up to version 4.7.21 should be aware of this weakness a [truncated]