Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
plone plone vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2020-7938
plone.restapi in Plone 5.2.0 up to and including 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.
Plone Plone
5
CVSSv2
CVE-2020-7940
Missing password strength checks on some forms in Plone 4.3 up to and including 5.2.0 allow users to set weak passwords, leading to easier cracking.
Plone Plone
6.5
CVSSv2
CVE-2020-28734
Plone prior to 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
Plone Plone
6.5
CVSSv2
CVE-2020-28735
Plone prior to 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
Plone Plone
6.5
CVSSv2
CVE-2020-28736
Plone prior to 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
Plone Plone
3.5
CVSSv2
CVE-2021-33513
Plone up to and including 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool.
Plone Plone
4.3
CVSSv2
CVE-2013-7062
Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x up to and including 3.3.6, 4.0.x up to and including 4.0.9, 4.1.x up to and including 4.1.6, 4.2.x up to and including 4.2.7, and 4.3 up to and including 4.3.2, allow remote malicious users to inj...
Plone Plone
3.5
CVSSv2
CVE-2021-3313
Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and the file upload functionality. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable c...
Plone Plone
4
CVSSv2
CVE-2021-33510
Plone up to and including 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file.
Plone Plone
5
CVSSv2
CVE-2021-33511
Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.
Plone Plone
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »