VulnSea

zope vulnerabilities

CVEs whose affected-version data names the zope package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

18 CVEsRSS

CVE-2024-51734Critical· 9.1
1y ago

Access control vulnerable to user data deletion by anonynmous users

Access control vulnerable to user data deletion by anonynmous users

Midnightaccesscontrol · accesscontrolEPSS 0.43%via OSV
CVE-2023-44389Low· 3.1
2y ago

Zope management interface vulnerable to stored cross site scripting via the title property

Zope management interface vulnerable to stored cross site scripting via the title property

Sunlitzope · zopeEPSS 0.40%via OSV
CVE-2023-42458Low· 3.7
3y ago

Zope vulnerable to Stored Cross Site Scripting with SVG images

Zope vulnerable to Stored Cross Site Scripting with SVG images

Sunlitzope · zopeEPSS 0.60%via OSV
CVE-2023-41050Medium· 6.8
3y ago

Information disclosure in AccessControl

Information disclosure in AccessControl

Sunlitaccesscontrol · accesscontrolEPSS 0.64%via OSV
CVE-2000-0483Medium
4y ago

Zope DocumentTemplate package allows unauthenticated write

Zope DocumentTemplate package allows unauthenticated write

Sunlitzope · zopeEPSS 3.0%via OSV
CVE-2000-0062High
4y ago

Zope DTML implementation Improper Authentication

Zope DTML implementation Improper Authentication

Twilightzope · zopeEPSS 2.2%via OSV
CVE-2002-0687Medium
4y ago

Zope Server vulnerable to DoS via header injection

Zope Server vulnerable to DoS via header injection

Sunlitzope · zopeEPSS 1.5%via OSV
CVE-2000-1211High
4y ago

Zope does not properly perform security registration for legacy names

Zope does not properly perform security registration for legacy names

Twilightzope · zopeEPSS 1.4%via OSV
CVE-2002-0170High
4y ago

Zope does not properly verify the access for objects with proxy roles

Zope does not properly verify the access for objects with proxy roles

Twilightzope · zopeEPSS 1.6%via OSV
CVE-2000-0725High
4y ago

Zope does not properly restrict access to the getRoles method

Zope does not properly restrict access to the getRoles method

Twilightzope · zopeEPSS 0.47%via OSV
CVE-2000-1212Medium
4y ago

Zope allows attackers to modify raw image and file data

Zope allows attackers to modify raw image and file data

Sunlitzope · zopeEPSS 1.5%via OSV
CVE-2002-0688High
4y ago

ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions

ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions

Twilightzope · zopeEPSS 1.4%via OSV
CVE-2011-4924Medium· 6.1
4y ago

Zope XSS Vulnerability

Zope XSS Vulnerability

Sunlitzope · zopeEPSS 1.4%via OSV
CVE-2021-32811High· 7.5
5y ago

Remote Code Execution via Script (Python) objects under Python 3

Remote Code Execution via Script (Python) objects under Python 3

Twilightzope · zopeEPSS 2.3%via OSV
CVE-2021-32807Medium· 4.4
5y ago

Remote Code Execution via unsafe classes in otherwise permitted modules

Remote Code Execution via unsafe classes in otherwise permitted modules

Sunlitaccesscontrol · accesscontrolEPSS 2.0%via OSV
CVE-2021-32633Medium· 6.8
5y ago

Remote Code Execution via traversal in TAL expressions

Remote Code Execution via traversal in TAL expressions

Sunlitzope · zopeEPSS 1.9%via OSV
CVE-2021-32674High· 8.8
5y ago

Remote Code Execution via traversal in TAL expressions

Remote Code Execution via traversal in TAL expressions

Twilightzope · zopeEPSS 1.6%via OSV
CVE-2010-3198None
16y ago

ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker thre…

ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.

Sunlitzope · zopeEPSS 1.5%via OSV
zope vulnerabilities (CVEs) · VulnSea