CVE-2026-16205

Summary

A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. Executing a manipulation of the argument Info can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
PluckCMS4.7.0affected
PluckCMS4.7.1affected
PluckCMS4.7.2affected
PluckCMS4.7.3affected
PluckCMS4.7.4affected
PluckCMS4.7.5affected
PluckCMS4.7.6affected
PluckCMS4.7.7affected
PluckCMS4.7.8affected
PluckCMS4.7.9affected
PluckCMS4.7.10affected
PluckCMS4.7.11affected
PluckCMS4.7.12affected
PluckCMS4.7.13affected
PluckCMS4.7.14affected
PluckCMS4.7.15affected
PluckCMS4.7.16affected
PluckCMS4.7.17affected
PluckCMS4.7.18affected
PluckCMS4.7.19affected
PluckCMS4.7.20affected
PluckCMS4.7.21affected

Weaknesses

  • CWE-79: Cross Site Scripting
  • CWE-94: Code Injection

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References