Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
plone plone vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2020-7939
SQL Injection in DTML or in connection objects in Plone 4.0 up to and including 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)
Plone Plone
6.5
CVSSv2
CVE-2020-7938
plone.restapi in Plone 5.2.0 up to and including 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.
Plone Plone
6.5
CVSSv2
CVE-2012-5489
The App.Undo.UndoSupport.get_request_var_or_attr function in Zope prior to 2.12.21 and 3.13.x prior to 2.13.11, as used in Plone prior to 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.
Plone Plone 4.2
Plone Plone 4.1.6
Plone Plone 4.1.5
Plone Plone 4.1.4
Plone Plone 3.3.1
Plone Plone 3.3
Plone Plone 3.2.3
Plone Plone 3.2.2
Plone Plone 3.0.3
Plone Plone 3.0.2
Plone Plone 3.0.1
Plone Plone 3.0
Plone Plone 2.0.3
Plone Plone 2.0.2
Plone Plone 2.0.1
Plone Plone 2.0
Plone Plone
Plone Plone 4.1
Plone Plone 4.0.5
Plone Plone 3.3.4
Plone Plone 3.3.2
Plone Plone 3.2.1
6.5
CVSSv2
CVE-2013-4189
Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone 2.1 up to and including 4.1, 4.2.x up to and including 4.2.5, and 4.3.x up to and including 4.3.1 allow remote authenticated users with administrator access to a subtree to acce...
Plone Plone 4.0.3
Plone Plone 4.0.5
Plone Plone 3.0.2
Plone Plone 3.0.4
Plone Plone 3.1.4
Plone Plone 3.1.6
Plone Plone 3.3.1
Plone Plone 3.3.3
Plone Plone 2.5.2
Plone Plone 2.5.4
Plone Plone 4.0.6.1
Plone Plone 4.1
Plone Plone 3.0
Plone Plone 3.0.1
Plone Plone 3.2
Plone Plone 3.2.1
Plone Plone 3.2.2
Plone Plone 3.2.3
Plone Plone 2.1
Plone Plone 2.1.1
Plone Plone 2.1.2
Plone Plone 2.1.3
6.4
CVSSv2
CVE-2012-5486
ZPublisher.HTTPRequest._scrubHeader in Zope 2 prior to 2.13.19, as used in Plone prior to 4.3 beta 1, allows remote malicious users to inject arbitrary HTTP headers via a linefeed (LF) character.
Plone Plone 3.3
Plone Plone 1.0
Plone Plone 4.2
Plone Plone 4.0.5
Plone Plone 3.0.1
Plone Plone 1.0.3
Plone Plone 3.0
Plone Plone 3.2.3
Plone Plone 3.1.4
Plone Plone 3.1.5.1
Plone Plone 4.2.0.1
Plone Plone 2.1.4
Plone Plone 4.0.2
Plone Plone 4.2.1.1
Plone Plone 3.3.5
Plone Plone 3.0.6
Plone Plone 2.5.4
Plone Plone 3.2
Plone Plone 3.1.1
Plone Plone 4.3
Plone Plone 2.1.1
Plone Plone 3.3.4
6.4
CVSSv2
CVE-2006-4247
Unspecified vulnerability in the Password Reset Tool prior to 0.4.1 on Plone 2.5 and 2.5.1 Release Candidate allows malicious users to reset the passwords of other users, related to "an erroneous security declaration."
Plone Plone 2.5
Plone Plone 2.5.1 Rc
6
CVSSv2
CVE-2022-24740
Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-alpha.0, a user could have their authentication cookie replaced with an authentication cookie from another user, effectively giving them control of the other user...
Plone Volto 14.0.0
Plone Volto
Plone Volto 15.0.0
6
CVSSv2
CVE-2009-0662
The PlonePAS product 3.x prior to 3.9 and 3.2.x prior to 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.
Plone Plonepas 3.5
Plone Plonepas 3.4
Plone Plonepas 3.0
Plone Plonepas 3.1
Plone Plonepas 3.3
Plone Plonepas 3.2
5.8
CVSSv2
CVE-2021-32806
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Versions of Products.isurlinportal before 1.2.0 have an Open Redirect vulnerability. Various parts of Plone use the 'is url in portal' check for security, mostly to see if it is safe to redirect ...
Plone Isurlinportal
5.8
CVSSv2
CVE-2020-7936
An open redirect on the login form (and possibly other places) in Plone 4.0 up to and including 5.2.1 allows an malicious user to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.
Plone Plone
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »