Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
plone plone vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2020-7941
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 up to and including 5.2.1 allows users to PUT (overwrite) some content without needing write permission.
Plone Plone
5.4
CVSSv3
CVE-2021-3313
Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and the file upload functionality. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable c...
Plone Plone
8.8
CVSSv3
CVE-2020-28734
Plone prior to 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
Plone Plone
8.8
CVSSv3
CVE-2020-28735
Plone prior to 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
Plone Plone
7.5
CVSSv3
CVE-2021-33511
Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.
Plone Plone
5.4
CVSSv3
CVE-2021-33513
Plone up to and including 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool.
Plone Plone
5.4
CVSSv3
CVE-2021-33508
Plone up to and including 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item.
Plone Plone
9.9
CVSSv3
CVE-2021-33509
Plone up to and including 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.
Plone Plone
4.3
CVSSv3
CVE-2021-33510
Plone up to and including 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file.
Plone Plone
5.4
CVSSv3
CVE-2021-33512
Plone up to and including 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document.
Plone Plone
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-0044
remote code execution
CVE-2024-37080
CVE-2024-5182
CVE-2024-4390
CVE-2024-6100
brute force
CVE-2021-47581
file inclusion
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »