CVE-2025-70129Pluxml · Pluxml
Vulnerability data via NVD (ingested)
If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be automatically recognized for articles, such that an automated script is able to solve this anti-spam mechanism trivially and publish spam comments. The details of captcha challenge are exposed within document body of articles with comments & anti spam-captcha functionalities enabled, including "capcha-letter", "capcha-word" and "capcha-token" which can be used to construct a valid post request to publish a comment. As such, attackers can flood articles with automated spam comments, especially if there are no other web defenses available.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2025-70129product:"Pluxml Pluxml"http.html:"Pluxml"More intel sources (5)
vuln:CVE-2025-70129vulnerabilities.cve_id: CVE-2025-70129CVE-2025-70129CVE-2025-70129"CVE-2025-70129" exploit -site:nvd.nist.gov