0
I Use This!
Activity Not Available
Analyzed 3 months ago. based on code collected 4 months ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2012-2156 Apr 11, 2012 Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1 more...
1.0.4, 1.1.3, 1.0.3, 1.0.2
CVE-2012-1414 Oct 07, 2012 Cross-site request forgery (CSRF) vulnerability in manager/news.php in Plume CMS 1.2.4 and earlier allows remote attackers to hijack the authentication more...
1.0.4, 1.1.3, 1.0.3, 1.0.2
CVE-2011-3985 Nov 09, 2011 Cross-site scripting (XSS) vulnerability in Plume before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1.0.4, 1.1.3, 1.0.3, 1.0.2
CVE-2010-2294 Jun 15, 2010 Cross-site request forgery (CSRF) vulnerability in Plume CMS 1.2.4 and possibly earlier allows remote attackers to hijack the authentication of adminis more...
1.0.4, 1.1.3, 1.0.3, 1.0.2
CVE-2006-4533 Sep 01, 2006 Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 and earlier allow remote attackers to execute arbitrary PHP code via the _PX_conf more...
1.0.4, 1.0.3, 1.0.2
CVE-2006-3562 Jul 13, 2006 PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_p more...
1.0.4