CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-16205

lowCVSS 2.4covered by 1 sourcefirst seen 2026-07-19
A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. Executing a manipulation of the argument Info can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

⚡ Watch CVE-2026-16205

Get an email if CVE-2026-16205 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-16205

CVE.org record

Embed the live status

CVE-2026-16205 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-16205 status](https://www.csirts.com/badge/CVE-2026-16205)](https://www.csirts.com/cve/CVE-2026-16205)