CVE-2025-46099
n/a n/a, pluck 취약점
In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.
- 대응 우선순위
- 점검
- CVSS
- 7.2
- EPSS
- 0.46% 백분위 37.9% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2025.07.23