Plone / Plone
103 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-22889 | Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request. | HIGH | 7.5 | Mar 5, 2024 |
| CVE-2024-23756 | The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions… | HIGH | 7.5 | Feb 8, 2024 |
| CVE-2024-0669 | Cross-Frame Scripting (XFS) on Plone CMS | HIGH | 7.1 | Jan 18, 2024 |
| CVE-2021-33926 | An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.… | HIGH | 8.7 | Feb 17, 2023 |
| CVE-2022-23599 | Cross-site Scripting and Open Redirect in Products.ATContentTypes | MEDIUM | 5.3 | Jan 28, 2022 |
| CVE-2021-35959 | In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the descripti… | MEDIUM | 5.3 | Jun 30, 2021 |
| CVE-2021-33507 | Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS. | MEDIUM | 5.3 | May 21, 2021 |
| CVE-2021-33508 | Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item. | MEDIUM | 5.1 | May 21, 2021 |
| CVE-2021-33509 | Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script. | CRITICAL | 9.4 | May 21, 2021 |
| CVE-2021-33510 | Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file. | MEDIUM | 5.3 | May 21, 2021 |
| CVE-2021-33511 | Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterit… | HIGH | 8.7 | May 21, 2021 |
| CVE-2021-33512 | Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document. | MEDIUM | 5.1 | May 21, 2021 |
| CVE-2021-33513 | Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool. | MEDIUM | 5.1 | May 21, 2021 |
| CVE-2021-32633 | Remote Code Execution via traversal in TAL expressions | HIGH | 7.6 | May 21, 2021 |
| CVE-2021-3313 | Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and the file upload functionality. The user's… | MEDIUM | 5.3 | May 20, 2021 |
| CVE-2021-29002 | A stored cross-site scripting (XSS) vulnerability in Plone CMS 5.2.3 exists in site-controlpanel via the "form.widgets.site_title" parameter. | MEDIUM | 5.4 | Mar 24, 2021 |
| CVE-2021-21336 | Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager | HIGH | 7.1 | Mar 8, 2021 |
| CVE-2020-28736 | Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only availabl… | HIGH | 8.7 | Dec 30, 2020 |
| CVE-2020-28735 | Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role). | HIGH | 8.7 | Dec 30, 2020 |
| CVE-2020-28734 | Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role. | HIGH | 8.7 | Dec 30, 2020 |
| CVE-2020-35190 | The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker cont… | CRITICAL | 9.8 | Dec 17, 2020 |
| CVE-2020-7936 | plone: open redirection on the login form and possibly other places | MEDIUM | 5.3 | Jan 23, 2020 |
| CVE-2020-7937 | plone: XSS in the title field | MEDIUM | 5.3 | Jan 23, 2020 |
| CVE-2020-7938 | plone: privilege escalation in plone.restapi | HIGH | 8.7 | Jan 23, 2020 |
| CVE-2020-7939 | plone: SQL injection due to insufficient SQL quoting in DTML or in connection objects | HIGH | 8.7 | Jan 23, 2020 |
Showing 1 to 25 of 103 CVEs