Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
plone plone 3.0.5 vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2008-0164
Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote malicious users to (1) add arbitrary accounts via the join_form page and (2) change the privileges of arbitrary groups via the prefs_groups_overview page.
Plone Plone Cms 3.0.5
Plone Plone Cms 3.0.6
668
VMScore
CVE-2011-0720
Unspecified vulnerability in Plone 2.5 up to and including 4.0, as used in Conga, luci, and possibly other products, allows remote malicious users to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.
Plone Plone 3.0.2
Plone Plone 3.0.1
Plone Plone 3.1.1
Plone Plone 3.1.6
Plone Plone 3.3.1
Plone Plone 3.0.4
Plone Plone 2.5.1
Plone Plone 3.3.5
Plone Plone 3.0.6
Plone Plone 3.1.3
Plone Plone 3.2
Plone Plone 3.1.5.1
Plone Plone 3.3.3
Plone Plone 3.0
Plone Plone 2.5
Plone Plone 4.0
Plone Plone 3.0.3
Plone Plone 2.5.4
Plone Plone 3.0.5
Plone Plone 3.1
Plone Plone 3.2.2
Plone Plone 3.3
383
VMScore
CVE-2010-2422
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 up to and including 3.3.4 before hotfix 20100612 allows remote malicious users to inject arbitrary web script or HTML via the safe_html transform.
Plone Plone 2.1
Plone Plone 2.5
Plone Plone 2.5.2
Plone Plone 3.0.3
Plone Plone 3.0.5
Plone Plone 3.1.5.1
Plone Plone 3.1.7
Plone Plone 3.3
Plone Plone 3.3.2
Plone Plone 2.1.1
Plone Plone 2.1.2
Plone Plone 2.1.3
Plone Plone 2.1.4
Plone Plone 3.0.6
Plone Plone 3.1
Plone Plone 3.1.1
Plone Plone 3.1.2
Plone Plone 3.1.3
Plone Plone 3.3.4
Plone Plone 3.3.5
Plone Plone 2.5.4
Plone Plone 2.5.5
312
VMScore
CVE-2011-1949
Cross-site scripting (XSS) vulnerability in the safe_html filter in Products.PortalTransforms in Plone 2.1 up to and including 4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-2422.
Plone Plone 2.1.2
Plone Plone 2.5.2
Plone Plone 2.5.3
Plone Plone 3.1.6
Plone Plone 3.1.5.1
Plone Plone 3.3.1
Plone Plone 3.3
Plone Plone 3.3.3
Plone Plone 3.3.4
Plone Plone 2.5.4
Plone Plone 4.0.4
Plone Plone 4.0.5
Plone Plone 2.1.4
Plone Plone 2.1.3
Plone Plone 3.0
Plone Plone 3.0.1
Plone Plone 3.0.2
Plone Plone 3.1.4
Plone Plone 3.1.3
Plone Plone 3.2.3
Plone Plone 3.2.2
Plone Plone 2.5.5
585
VMScore
CVE-2013-4200
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 up to and including 4.1, 4.2.x up to and including 4.2.5, and 4.3.x up to and including 4.3.1 treats URLs starting with a space as a relative URL, which allows remote malicious users to bypass the allow_ex...
Plone Plone 3.3
Plone Plone 4.0.5
Plone Plone 3.0.1
Plone Plone 3.0
Plone Plone 3.2.3
Plone Plone 3.1.4
Plone Plone 3.1.5.1
Plone Plone 2.1.4
Plone Plone 4.0.2
Plone Plone 3.3.5
Plone Plone 3.0.6
Plone Plone 3.2
Plone Plone 3.1.1
Plone Plone 2.1.1
Plone Plone 3.3.4
Plone Plone 3.3.2
Plone Plone 4.0.4
Plone Plone 3.1.7
Plone Plone 4.1
Plone Plone 3.2.2
Plone Plone 2.1.2
Plone Plone 3.0.3
1 EDB exploit
445
VMScore
CVE-2012-5496
kupu_spellcheck.py in Kupu in Plone prior to 4.0 allows remote malicious users to cause a denial of service (ZServer thread lock) via a crafted URL.
Plone Plone
Plone Plone 3.3.4
Plone Plone 3.3.3
Plone Plone 3.3.2
Plone Plone 3.1.1
Plone Plone 3.1
Plone Plone 3.0.6
Plone Plone 3.0.5
Plone Plone 3.0.4
Plone Plone 2.1.2
Plone Plone 2.1.1
Plone Plone 2.1
Plone Plone 3.3.1
Plone Plone 3.2.3
Plone Plone 3.1.4
Plone Plone 3.1.2
Plone Plone 3.0.2
Plone Plone 3.0
Plone Plone 2.5.1
Plone Plone 2.1.4
Plone Plone 2.0.3
Plone Plone 2.0.1
383
VMScore
CVE-2013-4188
traverser.py in Plone 2.1 up to and including 4.1, 4.2.x up to and including 4.2.5, and 4.3.x up to and including 4.3.1 allows remote attackers with administrator privileges to cause a denial of service (infinite loop and resource consumption) via unspecified vectors related to &...
Plone Plone 4.3.1
Plone Plone 4.3
Plone Plone 4.0.3
Plone Plone 4.0.5
Plone Plone 4.1
Plone Plone 3.0.4
Plone Plone 3.0.6
Plone Plone 3.1.6
Plone Plone 3.2
Plone Plone 3.3.3
Plone Plone 3.3.5
Plone Plone 2.5.4
Plone Plone 2.1
Plone Plone 3.0
Plone Plone 3.0.1
Plone Plone 3.0.2
Plone Plone 3.0.3
Plone Plone 3.2.1
Plone Plone 3.2.2
Plone Plone 3.2.3
Plone Plone 3.3
Plone Plone 3.3.1
383
VMScore
CVE-2013-4190
Multiple cross-site scripting (XSS) vulnerabilities in (1) spamProtect.py, (2) pts.py, and (3) request.py in Plone 2.1 up to and including 4.1, 4.2.x up to and including 4.2.5, and 4.3.x up to and including 4.3.1 allow remote malicious users to inject arbitrary web script or HTML...
Plone Plone 4.2
Plone Plone 4.2.5
Plone Plone 4.2.1
Plone Plone 4.2.2
Plone Plone 4.2.3
Plone Plone 4.2.4
Plone Plone 4.3
Plone Plone 4.3.1
Plone Plone 4.0.4
Plone Plone 4.0.6.1
Plone Plone 3.0.5
Plone Plone 3.1
Plone Plone 3.1.5.1
Plone Plone 3.1.7
Plone Plone 3.3.2
Plone Plone 3.3.4
Plone Plone 2.5.5
Plone Plone 2.1.1
Plone Plone 3.0
Plone Plone 3.0.1
Plone Plone 3.0.2
Plone Plone 3.0.3
516
VMScore
CVE-2013-4191
zip.py in Plone 2.1 up to and including 4.1, 4.2.x up to and including 4.2.5, and 4.3.x up to and including 4.3.1 does not properly enforce access restrictions when including content in a zip archive, which allows remote malicious users to obtain sensitive information by reading ...
Plone Plone 4.3
Plone Plone 4.3.1
Plone Plone 4.2.1
Plone Plone 4.2.2
Plone Plone 4.2.3
Plone Plone 4.2.4
Plone Plone 4.2.5
Plone Plone 4.2
Plone Plone 4.0.1
Plone Plone 3.0
Plone Plone 3.0.2
Plone Plone 3.1
Plone Plone 3.1.2
Plone Plone 3.2.1
Plone Plone 3.2.3
Plone Plone 2.5
Plone Plone 2.5.2
Plone Plone 2.1.1
Plone Plone 2.1.3
Plone Plone 4.0.3
Plone Plone 4.0.4
Plone Plone 4.0.5
312
VMScore
CVE-2013-4199
(1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 up to and including 4.1, 4.2.x up to and including 4.2.5, and 4.3.x up to and including 4.3.1 allow remote authenticated users to cause a denial of service (resource consumption) via a large zip archive, which is expanded (de...
Plone Plone 4.2
Plone Plone 4.2.1
Plone Plone 4.2.2
Plone Plone 4.2.4
Plone Plone 4.2.3
Plone Plone 4.2.5
Plone Plone 4.3
Plone Plone 4.3.1
Plone Plone 4.0.6.1
Plone Plone 4.1
Plone Plone 3.0
Plone Plone 3.0.1
Plone Plone 3.1.7
Plone Plone 3.2
Plone Plone 3.2.1
Plone Plone 3.2.2
Plone Plone 3.2.3
Plone Plone 2.1
Plone Plone 2.1.1
Plone Plone 2.1.2
Plone Plone 2.1.3
Plone Plone 4.0.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
remote code execution
CVE-2024-34909
CVE-2024-3317
SSTI
CVE-2024-3400
CVE-2024-30051
wireless
CVE-2024-4622
CVE-2024-4908
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »