plone has 17 CVEs on record between 2018 and 2026. 1 was published in the last 90 days. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: plone (16), plone.app.textfield (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Weakness classes
Products
- plone 16
- plone.app.textfield 1
Worst active — by depth score
CVE-2006-4247Critical· 9.1Plone allows anonymous users to reset any users password through the web via Password Reset Tool50CVE-2020-28736High· 8.8Improper Restriction of XML External Entity Reference in Plone49CVE-2020-28735High· 8.8SSRF attacks via tracebacks in Plone49CVE-2020-28734High· 8.8Improper Restriction of XML External Entity Reference in Plone49CVE-2024-22889Medium· 5.5Phone information disclosure vulnerability42
plone vulnerabilities
CVEs affecting plone, newest first. Open any entry for full detail, references, and exploit status.
17 CVEsRSS
CVE-2026-54503Medium· 4.3plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type
plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on the release line, RichTextValue.output returns an unsanitized stored…
CVE-2024-22889Medium· 5.5PoCPhone information disclosure vulnerability
Phone information disclosure vulnerability
CVE-2024-0669High· 7.1Cross-Frame Scripting vulnerability has been found on Plone CMS
Cross-Frame Scripting vulnerability has been found on Plone CMS
CVE-2011-4030HighPlone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
CVE-2011-1340MediumPlone XSS Vulnerability
Plone XSS Vulnerability
CVE-2008-4571MediumPlone Cross-site Scripting vulnerability in the LiveSearch module
Plone Cross-site Scripting vulnerability in the LiveSearch module
CVE-2006-4249Medium· 5.9Plone allows a user to masquerade as a group
Plone allows a user to masquerade as a group
CVE-2006-4247Critical· 9.1Plone allows anonymous users to reset any users password through the web via Password Reset Tool
Plone allows anonymous users to reset any users password through the web via Password Reset Tool
CVE-2008-0164High· 7.5Plone Cross-site request forgery (CSRF)
Plone Cross-site request forgery (CSRF)
CVE-2008-1394HighPlone CMS Improper Session Management
Plone CMS Improper Session Management
CVE-2006-1711MediumPoCPlone allows remote users to modify arbitrary portraits
Plone allows remote users to modify arbitrary portraits
CVE-2008-1396MediumPlone credentials stored in session cookie
Plone credentials stored in session cookie
CVE-2008-1393HighPlone Improper Session Management
Plone Improper Session Management
CVE-2020-28735High· 8.8SSRF attacks via tracebacks in Plone
SSRF attacks via tracebacks in Plone
CVE-2020-28734High· 8.8Improper Restriction of XML External Entity Reference in Plone
Improper Restriction of XML External Entity Reference in Plone
CVE-2020-28736High· 8.8Improper Restriction of XML External Entity Reference in Plone
Improper Restriction of XML External Entity Reference in Plone
CVE-2011-2528HighHigh severity vulnerability that affects Plone and Zope2
High severity vulnerability that affects Plone and Zope2