Skip to main content

Vendor archive

plone CVEs

Beta · best-effort

116 CVEs tagged to vendor plone7 Critical, 21 High, 84 Medium, 4 Low, 0 Unrated.

CVE-2026-28413

Published Mar 5, 2026

Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redirect to an ex…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-22889

Published Mar 6, 2024

Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23756

Published Feb 8, 2024

The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23054

Published Feb 5, 2024

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not exi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-23055

Published Jan 25, 2024

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0669

Published Jan 18, 2024

A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and exec…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42457

Published Sep 21, 2023

plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and prior to versions 2.0.1 and 3.0.1, when the `++api++` trave…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41048

Published Sep 21, 2023

plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity content. Prior to versions 5.6.1, 6.0.3, 6.1.3, and 6.2.1, there…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-33926

Published Feb 17, 2023

An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24740

Published Mar 14, 2022

Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-alpha.0, a user could have their authentication cookie replac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23599

Published Jan 28, 2022

Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products.ATContentTypes prior to version 3.0.6 are vulnerable to re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32806

Published Aug 2, 2021

Products.isurlinportal is a replacement for isURLInPortal method in Plone. Versions of Products.isurlinportal prior to 1.2.0 have an Open Redirect vulnerability. Various parts of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35959

Published Jun 30, 2021

In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33513

Published May 21, 2021

Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33512

Published May 21, 2021

Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33511

Published May 21, 2021

Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-33510

Published May 21, 2021

Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33509

Published May 21, 2021

Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-33508

Published May 21, 2021

Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33507

Published May 21, 2021

Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32633

Published May 21, 2021

Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules indirectly through Python modules that are available for d…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3313

Published May 20, 2021

Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and the file upload functionality. The user's input data is not p…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29002

Published Mar 24, 2021

A stored cross-site scripting (XSS) vulnerability in Plone CMS 5.2.3 exists in site-controlpanel via the "form.widgets.site_title" parameter.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28736

Published Dec 30, 2020

Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager rol…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 116 CVEsPage 1 of 5