← Back

Pligg Cms

pligg_cms

Vendor: Pligg • 43 CVEs

CVEs (43)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pligg
1Pligg Cms
Apr 21, 2025
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?id=0&list=whitelist&remove=pligg.com
1Pligg
1Pligg Cms
Apr 21, 2025
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karma
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php?action=save&var_id=32
1Pligg
1Pligg Cms
Mar 26, 2025
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=remove&widget=Statistics
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akismet
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?mode=delete&group_id=3
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall
1Pligg
1Pligg Cms
Aug 21, 2024
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php.
1Pligg
1Pligg Cms
Nov 21, 2024
Jul 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php.
1Pligg
1Pligg Cms
Nov 21, 2024
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_groups.php.
1Pligg
1Pligg Cms
Nov 21, 2024
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_topusers.php.
1Pligg
1Pligg Cms
May 6, 2026
Aug 31, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php.