CVE-2011-2528High▾ TwilightHigh severity vulnerability that affects Plone and Zope2
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.0%
2.0% → 2.0%
Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix20110720 for Plone 3.x allows attackers to gain privileges via unspecified vectors, related to a "highly serious vulnerability." NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-0720.
plone >= 3.3.2, < 3.3.6zope2 >= 2.12.0, < 2.12.19zope2 >= 2.13.0, < 2.13.8Upgrade to a patched release:
plone 3.3.6zope2 2.12.19zope2 2.13.8Connected by shared product, vendor, weakness, or advisory.
CVE-2006-4249Medium· 5.9Plone allows a user to masquerade as a group
CVE-2006-4247Critical· 9.1Plone allows anonymous users to reset any users password through the web via Password Reset Tool
CVE-2008-0164High· 7.5Plone Cross-site request forgery (CSRF)
CVE-2024-22889Medium· 5.5Phone information disclosure vulnerability
CVE-2020-28735High· 8.8SSRF attacks via tracebacks in Plone
CVE-2020-28734High· 8.8Improper Restriction of XML External Entity Reference in Plone