VYPR

Plone

by Plone (software)

pypi: plone

Source repositories

CVEs (109)

  • CVE-2021-33509CriMay 21, 2021
    risk 0.65cvss 9.9epss 0.02

    Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.

  • CVE-2020-35190CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank…

  • CVE-2020-7941CriJan 23, 2020
    risk 0.64cvss 9.8epss 0.02

    A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.

  • CVE-2015-7293HigSep 25, 2017
    risk 0.60cvss 8.8epss 0.03

    Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.

  • CVE-2021-33926HigFeb 17, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7,…

  • CVE-2020-28736HigDec 30, 2020
    risk 0.57cvss 8.8epss 0.01

    Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).

  • CVE-2020-28735HigDec 30, 2020
    risk 0.57cvss 8.8epss 0.01

    Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).

  • CVE-2020-28734HigDec 30, 2020
    risk 0.57cvss 8.8epss 0.01

    Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.

  • CVE-2020-7939HigJan 23, 2020
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)

  • CVE-2024-22889HigMar 6, 2024
    risk 0.49cvss 7.5epss 0.01

    Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.

  • CVE-2024-23756HigFeb 8, 2024
    risk 0.49cvss 7.5epss 0.01

    The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.

  • CVE-2021-33511HigMay 21, 2021
    risk 0.49cvss 7.5epss 0.01

    Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.

  • CVE-2020-7940HigJan 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.

  • CVE-2015-7318HigSep 25, 2017
    risk 0.49cvss 7.5epss 0.02

    Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.

  • CVE-2016-4041HigFeb 24, 2017
    risk 0.48cvss 7.3epss 0.01

    Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors.

  • CVE-2015-7317MedSep 25, 2017
    risk 0.44cvss 6.8epss 0.02

    Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 allows remote authenticated users to edit Kupu settings.

  • CVE-2017-1000483MedJan 3, 2018
    risk 0.42cvss 6.5epss 0.01

    Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.

  • CVE-2024-0669MedJan 18, 2024
    risk 0.41cvss 6.3epss 0.00

    A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.

  • CVE-2024-23055MedJan 25, 2024
    risk 0.40cvss 6.1epss 0.01

    An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.

  • CVE-2021-33507MedMay 21, 2021
    risk 0.40cvss 6.1epss 0.01

    Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.

Page 1 of 6