{"id":"CVE-2024-0669","aliases":["GHSA-5xfx-55x4-j223","PYSEC-2026-1797"],"title":"Cross-Frame Scripting vulnerability has been found on Plone CMS","summary":"Cross-Frame Scripting vulnerability has been found on Plone CMS","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","vendor":"plone","product":"plone","ecosystem":"pip","affected":["plone < 6.0.7"],"patched":["plone 6.0.7"],"published":"2024-01-18","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:04.905789082Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-5xfx-55x4-j223","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-0669"},{"url":"https://github.com/plone/Plone"},{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/cross-frame-scripting-xfs-plone-cms"}],"tags":["osv","pip"],"epss":0.00291,"epssPercentile":0.2198,"ingestedAt":"2026-07-08T18:25:46.242Z","slug":"CVE-2024-0669","body":"## Overview\n\nA Cross-Frame Scripting vulnerability has been found on Plone CMS affecting version below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.\n\n## Affected packages\n\n- `plone < 6.0.7`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `plone 6.0.7`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}