📦

pligg_cms

Vendor: pligg

Actively Exploited 0 CISA KEV List
PoC / Exploits 13 Code Available
Total RCEs 1 Remote Access
Total CVEs 753 Total Indexed
Avg. EPSS 1.19% Exploit Prob.
Latest CVE CVE-2024-42619 Aug 20

Security Vulnerability Index

Page 5 / 76
7.5 CVSS
CVE-2008-3366
Exploit Found

SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2008-1774.

EPSS: 1.01%
7.5 CVSS
CVE-2008-1774
Exploit Found

SQL injection vulnerability in editlink.php in Pligg 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: 0.97%
7.5 CVSS
CVE-2007-5579
Exploit Found

login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote attackers with knowledge of a username to reset that user's password by calculating the confirmationcode parameter.

EPSS: 2.35%