Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-57576Medium· 6.5plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and 5.0.0, …
CVE-2026-57149Critical· 9.9plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic por…
CVE-2026-54503Medium· 4.3plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on the release line, RichTextValue.output returns an unsanitized stored…
CVE-2024-22889Medium· 5.5PoCPhone information disclosure vulnerability
CVE-2024-0669High· 7.1Cross-Frame Scripting vulnerability has been found on Plone CMS
CVE-2011-4030HighPlone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
CVE-2011-1340MediumPlone XSS Vulnerability
CVE-2008-4571MediumPlone Cross-site Scripting vulnerability in the LiveSearch module
CVE-2006-4249Medium· 5.9Plone allows a user to masquerade as a group
CVE-2006-4247Critical· 9.1Plone allows anonymous users to reset any users password through the web via Password Reset Tool
CVE-2008-0164High· 7.5Plone Cross-site request forgery (CSRF)
CVE-2008-1394HighPlone CMS Improper Session Management
CVE-2006-1711MediumPoCPlone allows remote users to modify arbitrary portraits
CVE-2008-1396MediumPlone credentials stored in session cookie
CVE-2008-1393HighPlone Improper Session Management
CVE-2020-28735High· 8.8SSRF attacks via tracebacks in Plone
CVE-2020-28734High· 8.8Improper Restriction of XML External Entity Reference in Plone
CVE-2020-28736High· 8.8Improper Restriction of XML External Entity Reference in Plone
CVE-2011-2528HighHigh severity vulnerability that affects Plone and Zope2
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.