VYPR

Plone

by Plone (software)

pypi: plone

Source repositories

CVEs (109)

  • CVE-2015-7316MedSep 25, 2017
    risk 0.33cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x before 4.3.7, and 5.0rc1.

  • CVE-2015-7315MedSep 25, 2017
    risk 0.32cvss 5.9epss 0.02

    Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.

  • CVE-2016-7135MedMar 7, 2017
    risk 0.32cvss 4.9epss 0.03

    Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a .. (dot dot) in the path parameter in a getFile action to Plone/++theme++barceloneta/@@plone.resourceeditor.filemanager-actions.

  • CVE-2016-4043MedFeb 24, 2017
    risk 0.32cvss 4.9epss 0.01

    Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.

  • CVE-2021-33510MedMay 21, 2021
    risk 0.28cvss 4.3epss 0.01

    Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file.

  • CVE-2017-1000482MedJan 3, 2018
    risk 0.28cvss 5.4epss 0.01

    A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.

  • CVE-2022-23599MedJan 28, 2022
    risk 0.21cvss 4.3epss 0.01

    Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products.ATContentTypes prior to version 3.0.6 are vulnerable to reflected cross site scripting and open redirect when an attacker can get a compromised version of the…

  • CVE-2017-5524MedMar 23, 2017
    risk 0.21cvss 4.3epss 0.02

    Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.

  • CVE-2013-4200Jan 21, 2014
    risk 0.03cvss epss 0.02

    The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows remote attackers to bypass the allow_external_login_sites filtering property, …

  • CVE-2006-1711Apr 11, 2006
    risk 0.03cvss epss 0.04

    Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.

  • CVE-2011-3587Oct 10, 2011
    risk 0.02cvss epss 0.78

    Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.

  • CVE-2020-7938HigJan 23, 2020
    risk 0.00cvss 8.8epss 0.01

    plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.

  • CVE-2012-6661Nov 3, 2014
    risk 0.00cvss epss 0.02

    Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to…

  • CVE-2012-5508Nov 3, 2014
    risk 0.00cvss epss 0.02

    The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password resets via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6661 was…

  • CVE-2012-5500Nov 3, 2014
    risk 0.00cvss epss 0.01

    The batch id change script (renameObjectsByPaths.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to change the titles of content items by leveraging a valid CSRF token in a crafted request.

  • CVE-2012-5507Sep 30, 2014
    risk 0.00cvss epss 0.01

    AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.

  • CVE-2012-5506Sep 30, 2014
    risk 0.00cvss epss 0.02

    python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (infinite loop) via an RSS feed request for a folder the user does not have permission to access.

  • CVE-2012-5505Sep 30, 2014
    risk 0.00cvss epss 0.01

    atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a request for a view without a name.

  • CVE-2012-5504Sep 30, 2014
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in widget_traversal.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-5503Sep 30, 2014
    risk 0.00cvss epss 0.02

    ftp.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read hidden folder contents via unspecified vectors.

Page 3 of 6