VYPR
Vendor

Plone (software)

Plone is a free and open source content management system (CMS) built on top of the Zope application server. Plone is positioned as an enterprise CMS and is commonly used for intranets and as part of the web presence of large organizations. High-profile public sector users include the U.S. Federal Bureau of Investigation, Brazilian Government, United Nations, City of Bern (Switzerland), New South Wales Government (Australia), and European Environment Agency. Plone's proponents cite its security track record and its accessibility as reasons to choose Plone.

Products
24
CVEs
123
Across products
135
Status
Private

Products

24

Recent CVEs

123
View all 123 CVEs →
  • CVE-2021-33509CriMay 21, 2021
    risk 0.65cvss 9.9epss 0.02

    Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.

  • CVE-2024-23054CriFeb 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).

  • CVE-2020-35190CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank…

  • CVE-2020-7941CriJan 23, 2020
    risk 0.64cvss 9.8epss 0.02

    A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.

  • CVE-2015-7293HigSep 25, 2017
    risk 0.60cvss 8.8epss 0.03

    Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.

  • CVE-2026-57149CriSep 22, 2026
    risk 0.57cvss 9.9epss 0.01

    plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic portlet (plone.app.portlets.portlets.classic)…

  • CVE-2021-33926HigFeb 17, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7,…

  • CVE-2020-28736HigDec 30, 2020
    risk 0.57cvss 8.8epss 0.01

    Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).

  • CVE-2020-28735HigDec 30, 2020
    risk 0.57cvss 8.8epss 0.01

    Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).

  • CVE-2020-28734HigDec 30, 2020
    risk 0.57cvss 8.8epss 0.01

    Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.

  • CVE-2020-7939HigJan 23, 2020
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)

  • CVE-2020-7938HigJan 23, 2020
    risk 0.57cvss 8.8epss 0.01

    plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.

  • CVE-2026-55248CriAug 28, 2026
    risk 0.52cvss 9.1epss 0.00

    plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portlets/rss.py to download and retain…

  • CVE-2026-55247CriAug 28, 2026
    risk 0.52cvss 9.1epss 0.00

    plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events,…

  • CVE-2025-61668HigOct 2, 2025
    risk 0.50cvss —epss 0.00

    Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error…

  • CVE-2024-22889HigMar 6, 2024
    risk 0.49cvss 7.5epss 0.01

    Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.

  • CVE-2024-23756HigFeb 8, 2024
    risk 0.49cvss 7.5epss 0.01

    The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.

  • CVE-2021-33511HigMay 21, 2021
    risk 0.49cvss 7.5epss 0.01

    Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.

  • CVE-2020-7940HigJan 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.

  • CVE-2015-7318HigSep 25, 2017
    risk 0.49cvss 7.5epss 0.02

    Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.