---
id: CVE-2021-33507
aliases:
  - GHSA-35rg-466w-77h3
  - PYSEC-2021-79
  - PYSEC-2026-2961
  - PYSEC-2026-2967
title: 'Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone'
summary: 'Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone'
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
vendor: products-cmfcore
product: products-cmfcore
ecosystem: pip
affected:
  - products-cmfcore < 2.5.1
  - products-pluggableauthservice < 2.6.2
  - plone <= 5.2.4
patched:
  - products-cmfcore 2.5.1
  - products-pluggableauthservice 2.6.2
published: '2021-06-18'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-35rg-466w-77h3'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-33507'
  - url: 'https://github.com/advisories/GHSA-35rg-466w-77h3'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-79.yaml
  - url: 'https://plone.org/security/hotfix/20210518/reflected-xss-in-various-spots'
  - url: 'http://www.openwall.com/lists/oss-security/2021/05/22/1'
tags:
  - osv
  - pip
epss: 0.0075
epssPercentile: 0.52991
ingestedAt: '2026-07-13T18:57:51.653Z'
---

## Overview

Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.

## Affected packages

- `products-cmfcore < 2.5.1`
- `products-pluggableauthservice < 2.6.2`
- `plone <= 5.2.4`

## Remediation

Upgrade to a patched release:

- `products-cmfcore 2.5.1`
- `products-pluggableauthservice 2.6.2`
