plone vulnerabilities
CVEs whose affected-version data names the plone package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
23 CVEsRSS
CVE-2024-22889Medium· 5.5PoCPhone information disclosure vulnerability
Phone information disclosure vulnerability
CVE-2024-0669High· 7.1Cross-Frame Scripting vulnerability has been found on Plone CMS
Cross-Frame Scripting vulnerability has been found on Plone CMS
CVE-2020-7938High· 8.8Plone Privilege Escallation
Plone Privilege Escallation
CVE-2015-7315Medium· 5.9Plone unauthorized member addition vulnerability
Plone unauthorized member addition vulnerability
CVE-2011-4030HighPlone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
CVE-2011-1340MediumPlone XSS Vulnerability
Plone XSS Vulnerability
CVE-2017-1000481Medium· 6.1Products.CMFPlone Open Redirect Vulnerability
Products.CMFPlone Open Redirect Vulnerability
CVE-2017-1000482Medium· 5.4Products.CMFPlone XSS in profile home_page property
Products.CMFPlone XSS in profile home_page property
CVE-2008-4571MediumPlone Cross-site Scripting vulnerability in the LiveSearch module
Plone Cross-site Scripting vulnerability in the LiveSearch module
CVE-2006-4249Medium· 5.9Plone allows a user to masquerade as a group
Plone allows a user to masquerade as a group
CVE-2006-4247Critical· 9.1Plone allows anonymous users to reset any users password through the web via Password Reset Tool
Plone allows anonymous users to reset any users password through the web via Password Reset Tool
CVE-2008-0164High· 7.5Plone Cross-site request forgery (CSRF)
Plone Cross-site request forgery (CSRF)
CVE-2008-1394HighPlone CMS Improper Session Management
Plone CMS Improper Session Management
CVE-2006-1711MediumPoCPlone allows remote users to modify arbitrary portraits
Plone allows remote users to modify arbitrary portraits
CVE-2008-1396MediumPlone credentials stored in session cookie
Plone credentials stored in session cookie
CVE-2008-1393HighPlone Improper Session Management
Plone Improper Session Management
CVE-2021-33507Medium· 6.1Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone
Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone
CVE-2020-28735High· 8.8SSRF attacks via tracebacks in Plone
SSRF attacks via tracebacks in Plone
CVE-2020-28734High· 8.8Improper Restriction of XML External Entity Reference in Plone
Improper Restriction of XML External Entity Reference in Plone
CVE-2020-28736High· 8.8Improper Restriction of XML External Entity Reference in Plone
Improper Restriction of XML External Entity Reference in Plone
CVE-2011-1948Medium· 6.1Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool
Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool
CVE-2011-1950Medium· 6.5⚠ ExploitedPlone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts
Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts
CVE-2011-2528HighHigh severity vulnerability that affects Plone and Zope2
High severity vulnerability that affects Plone and Zope2