CVE-2014-8708

Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.