VulnSea

plone vulnerabilities

CVEs whose affected-version data names the plone package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

23 CVEsRSS

CVE-2024-22889Medium· 5.5PoC
2y ago

Phone information disclosure vulnerability

Phone information disclosure vulnerability

Twilightplone · ploneEPSS 0.70%via OSV
CVE-2024-0669High· 7.1
2y ago

Cross-Frame Scripting vulnerability has been found on Plone CMS

Cross-Frame Scripting vulnerability has been found on Plone CMS

Twilightplone · ploneEPSS 0.29%via OSV
CVE-2020-7938High· 8.8
4y ago

Plone Privilege Escallation

Plone Privilege Escallation

Twilightplone-restapi · plone-restapiEPSS 1.5%via OSV
CVE-2015-7315Medium· 5.9
4y ago

Plone unauthorized member addition vulnerability

Plone unauthorized member addition vulnerability

Sunlitproducts-cmfplone · products-cmfploneEPSS 2.1%via OSV
CVE-2011-4030High
4y ago

Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable

Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable

Twilightplone · ploneEPSS 2.0%via OSV
CVE-2011-1340Medium
4y ago

Plone XSS Vulnerability

Plone XSS Vulnerability

Sunlitplone · ploneEPSS 1.2%via OSV
CVE-2017-1000481Medium· 6.1
4y ago

Products.CMFPlone Open Redirect Vulnerability

Products.CMFPlone Open Redirect Vulnerability

Sunlitproducts-cmfplone · products-cmfploneEPSS 0.89%via OSV
CVE-2017-1000482Medium· 5.4
4y ago

Products.CMFPlone XSS in profile home_page property

Products.CMFPlone XSS in profile home_page property

Sunlitproducts-cmfplone · products-cmfploneEPSS 0.69%via OSV
CVE-2008-4571Medium
4y ago

Plone Cross-site Scripting vulnerability in the LiveSearch module

Plone Cross-site Scripting vulnerability in the LiveSearch module

Sunlitplone · ploneEPSS 1.2%via OSV
CVE-2006-4249Medium· 5.9
4y ago

Plone allows a user to masquerade as a group

Plone allows a user to masquerade as a group

Sunlitplone · ploneEPSS 1.0%via OSV
CVE-2006-4247Critical· 9.1
4y ago

Plone allows anonymous users to reset any users password through the web via Password Reset Tool

Plone allows anonymous users to reset any users password through the web via Password Reset Tool

Midnightplone · ploneEPSS 1.0%via OSV
CVE-2008-0164High· 7.5
4y ago

Plone Cross-site request forgery (CSRF)

Plone Cross-site request forgery (CSRF)

Twilightplone · ploneEPSS 0.65%via OSV
CVE-2008-1394High
4y ago

Plone CMS Improper Session Management

Plone CMS Improper Session Management

Twilightplone · ploneEPSS 1.4%via OSV
CVE-2006-1711MediumPoC
4y ago

Plone allows remote users to modify arbitrary portraits

Plone allows remote users to modify arbitrary portraits

Twilightplone · ploneEPSS 3.9%via OSV
CVE-2008-1396Medium
4y ago

Plone credentials stored in session cookie

Plone credentials stored in session cookie

Sunlitplone · ploneEPSS 1.1%via OSV
CVE-2008-1393High
4y ago

Plone Improper Session Management

Plone Improper Session Management

Twilightplone · ploneEPSS 2.9%via OSV
CVE-2021-33507Medium· 6.1
5y ago

Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone

Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone

Sunlitproducts-cmfcore · products-cmfcoreEPSS 0.75%via OSV
CVE-2020-28735High· 8.8
5y ago

SSRF attacks via tracebacks in Plone

SSRF attacks via tracebacks in Plone

Twilightplone · ploneEPSS 1.4%via OSV
CVE-2020-28734High· 8.8
5y ago

Improper Restriction of XML External Entity Reference in Plone

Improper Restriction of XML External Entity Reference in Plone

Twilightplone · ploneEPSS 1.4%via OSV
CVE-2020-28736High· 8.8
5y ago

Improper Restriction of XML External Entity Reference in Plone

Improper Restriction of XML External Entity Reference in Plone

Twilightplone · ploneEPSS 1.4%via OSV
CVE-2011-1948Medium· 6.1
8y ago

Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool

Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool

Sunlitproducts-passwordresettool · products-passwordresettoolEPSS 2.4%via OSV
CVE-2011-1950Medium· 6.5⚠ Exploited
8y ago

Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts

Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts

Twilightplone-app-users · plone-app-usersEPSS 2.3%via OSV
CVE-2011-2528High
8y ago

High severity vulnerability that affects Plone and Zope2

High severity vulnerability that affects Plone and Zope2

Twilightplone · ploneEPSS 2.0%via OSV
plone vulnerabilities (CVEs) · VulnSea