← Back

Plone

plone

Vendor: Plone • 103 CVEs

CVEs (103)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Plone
1Plone
May 13, 2026
Mar 7, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via a...Show more
Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.Show less
1Plone
1Plone
May 13, 2026
Mar 7, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in...Show more
Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.Actions or the (3) came_from parameter to /login_form.Show less
1Plone
1Plone
May 13, 2026
Mar 7, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GET request.
1Plone
1Plone
May 13, 2026
Mar 7, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a .. (dot dot) in the path parameter in a getFile action to Plone/++theme...Show more
Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a .. (dot dot) in the path parameter in a getFile action to Plone/++theme++barceloneta/@@plone.resourceeditor.filemanager-actions.Show less
1Plone
1Plone
May 13, 2026
Feb 24, 2017
N/A· v4
4.9 MEDIUM· v3
3.5 LOW· v2
Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.
1Plone
1Plone
May 13, 2026
Feb 24, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors.
1Plone
1Plone
May 13, 2026
Feb 24, 2017
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors.
1Plone
1Plone
May 13, 2026
Feb 4, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the manage_findResult component in the search feature in Zope ZMI in Plone before 4.3.12 and 5.x before 5.0.7 allows remote attackers to inject arbitrary web script or HTML via...Show more
Cross-site scripting (XSS) vulnerability in the manage_findResult component in the search feature in Zope ZMI in Plone before 4.3.12 and 5.x before 5.0.7 allows remote attackers to inject arbitrary web script or HTML via vectors involving double quotes, as demonstrated by the obj_ids:tokens parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7140.Show less
2Plone
Zope
2Plone
Zope
May 6, 2026
Nov 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors....Show more
Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).Show less
1Plone
1Plone
May 6, 2026
Nov 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password resets via unspecified vectors. NOTE: this identifier was SPLIT per ADT2...Show more
The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password resets via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6661 was assigned for the PRNG reseeding issue in Zope.Show less
1Plone
1Plone
May 6, 2026
Nov 3, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The batch id change script (renameObjectsByPaths.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to change the titles of content items by leveraging a valid CSRF token in a crafted request.
2Plone
Zope
2Plone
Zope
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.
1Plone
1Plone
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (infinite loop) via an RSS feed request for a folder the user does not have permission to access.
1Plone
1Plone
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a request for a view without a name.
1Plone
1Plone
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in widget_traversal.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Plone
1Plone
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
ftp.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read hidden folder contents via unspecified vectors.
1Plone
1Plone
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in safe_html.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with permissions to edit content to inject arbitrary web script or HTML via unspecifi...Show more
Cross-site scripting (XSS) vulnerability in safe_html.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with permissions to edit content to inject arbitrary web script or HTML via unspecified vectors.Show less
1Plone
1Plone
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom content types via a crafted URL.
1Plone
1Plone
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (memory consumption) via a large value, related to formatColumns.
1Plone
1Plone
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a crafted request to a collection.