---
id: CVE-2011-2528
aliases:
  - GHSA-p6h9-hpcg-c6gm
  - PYSEC-2011-25
  - PYSEC-2011-32
  - PYSEC-2026-764
title: High severity vulnerability that affects Plone and Zope2
summary: High severity vulnerability that affects Plone and Zope2
severity: high
vendor: plone
product: plone
ecosystem: pip
affected:
  - 'plone >= 3.3.2, < 3.3.6'
  - 'zope2 >= 2.12.0, < 2.12.19'
  - 'zope2 >= 2.13.0, < 2.13.8'
patched:
  - plone 3.3.6
  - zope2 2.12.19
  - zope2 2.13.8
published: '2018-07-23'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-p6h9-hpcg-c6gm'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2011-2528'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=718824'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2011-25.yaml
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2011-32.yaml
  - url: 'https://mail.zope.org/pipermail/zope-announce/2011-June/002260.html'
  - url: 'https://plone.org/products/plone-hotfix/releases/20110622'
  - url: 'https://plone.org/products/plone/security/advisories/20110622'
  - url: 'https://www.openwall.com/lists/oss-security/2011/07/04/6'
  - url: 'https://www.openwall.com/lists/oss-security/2011/07/12/9'
  - url: 'http://plone.org/products/plone-hotfix/releases/20110622'
  - url: 'http://plone.org/products/plone/security/advisories/20110622'
  - url: 'http://secunia.com/advisories/45056'
  - url: 'http://secunia.com/advisories/45111'
  - url: 'http://www.openwall.com/lists/oss-security/2011/07/04/6'
  - url: 'http://www.openwall.com/lists/oss-security/2011/07/12/9'
tags:
  - osv
  - pip
epss: 0.02031
epssPercentile: 0.79928
ingestedAt: '2026-07-08T18:25:51.683Z'
---

## Overview

Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix20110720 for Plone 3.x allows attackers to gain privileges via unspecified vectors, related to a "highly serious vulnerability." NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-0720.

## Affected packages

- `plone >= 3.3.2, < 3.3.6`
- `zope2 >= 2.12.0, < 2.12.19`
- `zope2 >= 2.13.0, < 2.13.8`

## Remediation

Upgrade to a patched release:

- `plone 3.3.6`
- `zope2 2.12.19`
- `zope2 2.13.8`
