PT-2026-36805 · Pluck Cms · Pluck Cms

0Xnaka-Hax

·

Published

2026-05-04

·

Updated

2026-05-04

·

CVE-2026-31205

CVSS v3.1

5.7

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pluck CMS versions prior to 4.7.21dev
Description A Cross Site Scripting issue allows a remote attacker to escalate privileges. This occurs through the 'editpage.php' endpoint and the sanitizePageContent() function.
Recommendations Update to version 4.7.21dev or later. As a temporary workaround, restrict access to the 'editpage.php' endpoint or the sanitizePageContent() function to minimize the risk of exploitation.

Exploit

Fix

LPE

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-31205

Affected Products

Pluck Cms