V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
Filters

All vulnerabilities

118 / 118
Vendor: plone×Clear all
6.8
CVE-2011-3587DEB
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1,…
2011-01-01
EPSS78.5%
pct 99
5.0
CVE-2006-1711DEB
Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2)…
2006-01-01
EPSS3.9%
pct 88
7.5
CVE-2011-0720DEB
Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other …
2011-01-01
EPSS3.1%
pct 86
8.8
CVE-2015-7293CVE
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 a…
2015-01-01Pre-auth
EPSS3.1%
pct 85
10.0
CVE-2008-1393DEB
Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username …
2008-01-01
EPSS2.9%
pct 84
5.0
CVE-2012-5498CVE
queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass c…
2012-01-01
EPSS2.6%
pct 83
4.9
CVE-2016-7135CVE
Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allow…
2016-01-01
EPSS2.6%
pct 83
4.6
CVE-2012-5488CVE
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execut…
2012-01-01
EPSS2.5%
pct 82
4.3
CVE-2012-5486DEB
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta …
2012-01-01
EPSS2.4%
pct 82
5.0
CVE-2012-5499CVE
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause …
2012-01-01
EPSS2.4%
pct 82
4.3
CVE-2011-1948DEB
Cross-site scripting (XSS) vulnerability in Plone 4.1 and earlier allows remote attackers to in…
2011-01-01
EPSS2.4%
pct 81
5.8
CVE-2013-4200CVE
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x t…
2013-01-01
EPSS2.4%
pct 81
1.8
CVE-2012-6661DEB
Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the p…
2012-01-01
EPSS2.3%
pct 81
9.8
CVE-2020-7941CVE
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users …
2020-01-01Pre-auth
EPSS2.3%
pct 80
7.5
CVE-2007-5741DEB
Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Pyth…
2007-01-01
EPSS2.2%
pct 80
9.8
CVE-2020-35190CVE
The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a bl…
2020-01-01Pre-auth
EPSS2.2%
pct 79
5.0
CVE-2011-4462DEB
Plone 4.1.3 and earlier computes hash values for form parameters without restricting the abilit…
2011-01-01
EPSS2.2%
pct 79
5.0
CVE-2012-5497CVE
membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enume…
2012-01-01
EPSS2.1%
pct 79
6.0
CVE-2012-5485CVE
registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to exe…
2012-01-01
EPSS2.1%
pct 78
9.9
CVE-2021-33509CVE
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keywor…
2021-01-01
EPSS2.0%
pct 78
7.5
CVE-2011-2528DEB
Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used i…
2011-01-01
EPSS2.0%
pct 78
5.9
CVE-2015-7315CVE
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.…
2015-01-01Pre-auth
EPSS2.0%
pct 78
4.3
CVE-2011-4030DEB
The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not…
2011-01-01
EPSS2.0%
pct 77
8.8
CVE-2021-32633CVE
Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can…
2021-01-01
EPSS1.8%
pct 76
4.3
CVE-2013-4190CVE
Multiple cross-site scripting (XSS) vulnerabilities in (1) spamProtect.py, (2) pts.py, and (3) …
2013-01-01
EPSS1.8%
pct 75
6.0
CVE-2012-5493CVE
gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with cert…
2012-01-01
EPSS1.7%
pct 74
6.0
CVE-2012-5487DEB
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 …
2012-01-01
EPSS1.7%
pct 74
9.8
CVE-2024-23054CVE
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for…
2024-01-01Pre-auth
EPSS1.7%
pct 73
4.7
CVE-2016-7137CVE
Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and …
2016-01-01Pre-auth
EPSS1.7%
pct 73
7.5
CVE-2015-7318CVE
Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.
2015-01-01Pre-auth
EPSS1.7%
pct 73
5.0
CVE-2012-5495CVE
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execut…
2012-01-01
EPSS1.7%
pct 73
5.0
CVE-2012-5506CVE
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause …
2012-01-01
EPSS1.6%
pct 72
5.0
CVE-2012-5496CVE
kupu_spellcheck.py in Kupu in Plone before 4.0 allows remote attackers to cause a denial of ser…
2012-01-01
EPSS1.6%
pct 72
6.8
CVE-2015-7317CVE
Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 al…
2015-01-01
EPSS1.6%
pct 72
5.4
CVE-2016-7138CVE
Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x th…
2016-01-01
EPSS1.6%
pct 72
5.4
CVE-2016-7140CVE
Multiple cross-site scripting (XSS) vulnerabilities in the ZMI page in Zope2 in Plone CMS 5.x t…
2016-01-01
EPSS1.6%
pct 72
5.4
CVE-2016-7139CVE
Cross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x throu…
2016-01-01
EPSS1.6%
pct 72
5.4
CVE-2016-7136CVE
z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to condu…
2016-01-01
EPSS1.6%
pct 72
3.5
CVE-2011-1950DEB
plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties…
2011-01-01
EPSS1.6%
pct 72
1.8
CVE-2012-5508DEB
The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain ra…
2012-01-01
EPSS1.5%
pct 71
Select a vulnerability on the left to open the preview.