Total vulnerabilities in the database
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.
CVSS v3:
CVSS v2:
CWEs: