{"id":"CVE-2021-33507","aliases":["GHSA-35rg-466w-77h3","PYSEC-2021-79","PYSEC-2026-2961","PYSEC-2026-2967"],"title":"Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone","summary":"Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","vendor":"products-cmfcore","product":"products-cmfcore","ecosystem":"pip","affected":["products-cmfcore < 2.5.1","products-pluggableauthservice < 2.6.2","plone <= 5.2.4"],"patched":["products-cmfcore 2.5.1","products-pluggableauthservice 2.6.2"],"published":"2021-06-18","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-35rg-466w-77h3","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-33507"},{"url":"https://github.com/advisories/GHSA-35rg-466w-77h3"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-79.yaml"},{"url":"https://plone.org/security/hotfix/20210518/reflected-xss-in-various-spots"},{"url":"http://www.openwall.com/lists/oss-security/2021/05/22/1"}],"tags":["osv","pip"],"epss":0.0075,"epssPercentile":0.53489,"ingestedAt":"2026-07-13T18:57:51.653Z","slug":"CVE-2021-33507","body":"## Overview\n\nZope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.\n\n## Affected packages\n\n- `products-cmfcore < 2.5.1`\n- `products-pluggableauthservice < 2.6.2`\n- `plone <= 5.2.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `products-cmfcore 2.5.1`\n- `products-pluggableauthservice 2.6.2`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}