Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22449 | In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter. |
Tue, 14 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pluck-cms
Pluck-cms pluck |
|
| CPEs | cpe:2.3:a:pluck-cms:pluck:4.7.20:dev:*:*:*:*:*:* | |
| Vendors & Products |
Pluck-cms
Pluck-cms pluck |
Wed, 23 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 | |
| Metrics |
cvssV3_1
|
Wed, 23 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-07-23T13:54:38.642Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-46099
Updated: 2025-07-23T13:54:08.421Z
Status : Analyzed
Published: 2025-07-23T14:15:33.490
Modified: 2025-10-14T14:10:12.780
Link: CVE-2025-46099
No data.
OpenCVE Enrichment
No data.
EUVD