VulnSea

plone has 17 CVEs on record between 2018 and 2026. 1 was published in the last 90 days. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: plone (16), plone.app.textfield (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
1 prev 0

Weakness classes

Products

  • plone 16
  • plone.app.textfield 1
17
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

plone vulnerabilities

CVEs affecting plone, newest first. Open any entry for full detail, references, and exploit status.

17 CVEsRSS

CVE-2026-54503Medium· 4.3
1w ago

plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type

plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on the release line, RichTextValue.output returns an unsanitized stored…

Sunlitplone · plone.app.textfieldEPSS 0.23%via NVD
CVE-2024-22889Medium· 5.5PoC
2y ago

Phone information disclosure vulnerability

Phone information disclosure vulnerability

Twilightplone · ploneEPSS 0.70%via OSV
CVE-2024-0669High· 7.1
2y ago

Cross-Frame Scripting vulnerability has been found on Plone CMS

Cross-Frame Scripting vulnerability has been found on Plone CMS

Twilightplone · ploneEPSS 0.29%via OSV
CVE-2011-4030High
4y ago

Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable

Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable

Twilightplone · ploneEPSS 2.0%via OSV
CVE-2011-1340Medium
4y ago

Plone XSS Vulnerability

Plone XSS Vulnerability

Sunlitplone · ploneEPSS 1.2%via OSV
CVE-2008-4571Medium
4y ago

Plone Cross-site Scripting vulnerability in the LiveSearch module

Plone Cross-site Scripting vulnerability in the LiveSearch module

Sunlitplone · ploneEPSS 1.2%via OSV
CVE-2006-4249Medium· 5.9
4y ago

Plone allows a user to masquerade as a group

Plone allows a user to masquerade as a group

Sunlitplone · ploneEPSS 1.0%via OSV
CVE-2006-4247Critical· 9.1
4y ago

Plone allows anonymous users to reset any users password through the web via Password Reset Tool

Plone allows anonymous users to reset any users password through the web via Password Reset Tool

Midnightplone · ploneEPSS 1.0%via OSV
CVE-2008-0164High· 7.5
4y ago

Plone Cross-site request forgery (CSRF)

Plone Cross-site request forgery (CSRF)

Twilightplone · ploneEPSS 0.65%via OSV
CVE-2008-1394High
4y ago

Plone CMS Improper Session Management

Plone CMS Improper Session Management

Twilightplone · ploneEPSS 1.4%via OSV
CVE-2006-1711MediumPoC
4y ago

Plone allows remote users to modify arbitrary portraits

Plone allows remote users to modify arbitrary portraits

Twilightplone · ploneEPSS 3.9%via OSV
CVE-2008-1396Medium
4y ago

Plone credentials stored in session cookie

Plone credentials stored in session cookie

Sunlitplone · ploneEPSS 1.1%via OSV
CVE-2008-1393High
4y ago

Plone Improper Session Management

Plone Improper Session Management

Twilightplone · ploneEPSS 2.9%via OSV
CVE-2020-28735High· 8.8
5y ago

SSRF attacks via tracebacks in Plone

SSRF attacks via tracebacks in Plone

Twilightplone · ploneEPSS 1.4%via OSV
CVE-2020-28734High· 8.8
5y ago

Improper Restriction of XML External Entity Reference in Plone

Improper Restriction of XML External Entity Reference in Plone

Twilightplone · ploneEPSS 1.4%via OSV
CVE-2020-28736High· 8.8
5y ago

Improper Restriction of XML External Entity Reference in Plone

Improper Restriction of XML External Entity Reference in Plone

Twilightplone · ploneEPSS 1.4%via OSV
CVE-2011-2528High
8y ago

High severity vulnerability that affects Plone and Zope2

High severity vulnerability that affects Plone and Zope2

Twilightplone · ploneEPSS 2.0%via OSV
plone vulnerabilities (CVEs) · VulnSea