Skip to main content

Vendor archive

pligg CVEs

Beta · best-effort

44 CVEs tagged to vendor pligg3 Critical, 28 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2024-42619

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?id=0&list=whitelist&remove=pligg.com

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42612

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42621

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42618

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karma

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42617

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php?action=save&var_id=32

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42616

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=remove&widget=Statistics

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42613

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akismet

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42611

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42610

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42609

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42607

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42606

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42605

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42604

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?mode=delete&group_id=3

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42603

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42608

Published Aug 20, 2024

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37677

Published Jul 25, 2023

Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-34956

Published Aug 2, 2022

Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_groups.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-34955

Published Aug 2, 2022

Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_topusers.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6655

Published Aug 31, 2015

Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator vi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9096

Published Nov 26, 2014

Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) n parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2937

Published May 27, 2012

Multiple SQL injection vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) list parameter in a move action to admin/admi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2936

Published May 27, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) page parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2436

Published May 27, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter in a mov…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2435

Published May 27, 2012

Directory traversal vulnerability in the captcha module in Pligg CMS before 1.2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot)…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 44 CVEsPage 1 of 2