---
id: CVE-2008-4571
aliases:
  - GHSA-46f9-f8jm-mw2x
  - PYSEC-2026-730
title: Plone Cross-site Scripting vulnerability in the LiveSearch module
summary: Plone Cross-site Scripting vulnerability in the LiveSearch module
severity: medium
vendor: plone
product: plone
ecosystem: pip
affected:
  - plone < 3.0.4
patched:
  - plone 3.0.4
published: '2022-05-02'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-46f9-f8jm-mw2x'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2008-4571'
  - url: 'https://github.com/plone/Plone'
  - url: >-
      https://web.archive.org/web/20081012113150/http://secunia.com/advisories/28293
  - url: >-
      https://web.archive.org/web/20120705155735/http://www.securityfocus.com/bid/27098
  - url: 'http://dev.plone.org/plone/ticket/7439'
  - url: 'http://plone.org/products/plone/releases/3.0.4'
tags:
  - osv
  - pip
epss: 0.01154
epssPercentile: 0.6512
ingestedAt: '2026-07-08T18:25:45.268Z'
---

## Overview

Cross-site scripting (XSS) vulnerability in the LiveSearch module in Plone before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the Description field for search results, as demonstrated using the onerror Javascript even in an IMG tag.

## Affected packages

- `plone < 3.0.4`

## Remediation

Upgrade to a patched release:

- `plone 3.0.4`
