CVE-2026-16205: Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting
A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialcharsdecode of the file data/modules/albums/albums.admin.php of the component Albums Module. Executing a manipulation of the argument Info can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16205?
The severity of CVE-2026-16205 is low, rated at 2.4.
What vulnerabilities are associated with CVE-2026-16205?
CVE-2026-16205 is associated with cross site scripting (XSS) and code injection vulnerabilities.
How do I fix CVE-2026-16205?
To address CVE-2026-16205, update Pluck CMS to version 4.7.22 or later.
Which component of Pluck CMS is affected by CVE-2026-16205?
CVE-2026-16205 affects the Albums Module in Pluck CMS, specifically the file albums.admin.php.
What can exploitation of CVE-2026-16205 lead to?
Exploitation of CVE-2026-16205 can lead to cross site scripting attacks through manipulation of the argument Info.