products-cmfcore vulnerabilities
CVEs whose affected-version data names the products-cmfcore package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2023-36814High· 7.5Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module
Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module
▾ Twilightproducts-cmfcore · products-cmfcoreEPSS 0.72%via OSV
CVE-2021-33507Medium· 6.1Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone
Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone
▾ Sunlitproducts-cmfcore · products-cmfcoreEPSS 0.75%via OSV