---
id: CVE-2009-5145
aliases:
  - GHSA-5r4x-qc7q-vj27
  - PYSEC-2026-763
title: Zope Cross-site scripting (XSS) vulnerability in ZMI pages
summary: Zope Cross-site scripting (XSS) vulnerability in ZMI pages
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
vendor: zope2
product: zope2
ecosystem: pip
affected:
  - zope2 < 2.12.5
patched:
  - zope2 2.12.5
published: '2022-05-02'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-5r4x-qc7q-vj27'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2009-5145'
  - url: >-
      https://github.com/zopefoundation/Zope/commit/2abdf14620f146857dc8e3ffd2b6a754884c331d
  - url: 'https://bugs.launchpad.net/zope2/+bug/490514'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/zope/PYSEC-2017-148.yaml
  - url: 'https://github.com/zopefoundation/Zope'
  - url: 'https://security-tracker.debian.org/tracker/CVE-2009-5145'
  - url: 'http://cve.killedkenny.io/cve/CVE-2009-5145'
  - url: 'http://www.openwall.com/lists/oss-security/2015/03/02/7'
tags:
  - osv
  - pip
epss: 0.02436
epssPercentile: 0.83438
ingestedAt: '2026-07-08T18:25:46.056Z'
---

## Overview

Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4, 2.10.2, 2.10.1, 2.12.

## Affected packages

- `zope2 < 2.12.5`

## Remediation

Upgrade to a patched release:

- `zope2 2.12.5`
