CVE-2024-22889
- EPSS 0.47%
- Veröffentlicht 06.03.2024 00:15:52
- Zuletzt bearbeitet 21.01.2025 16:53:16
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.
CVE-2024-23756
- EPSS 0.22%
- Veröffentlicht 08.02.2024 21:15:08
- Zuletzt bearbeitet 15.05.2025 20:15:44
The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.
CVE-2024-0669
- EPSS 0.05%
- Veröffentlicht 18.01.2024 13:15:09
- Zuletzt bearbeitet 21.11.2024 08:47:06
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.
CVE-2021-33926
- EPSS 0.21%
- Veröffentlicht 17.02.2023 18:15:11
- Zuletzt bearbeitet 19.03.2025 15:15:36
An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1...
CVE-2022-23599
- EPSS 0.32%
- Veröffentlicht 28.01.2022 22:15:17
- Zuletzt bearbeitet 05.05.2025 17:17:57
Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products.ATContentTypes prior to version 3.0.6 are vulnerable to reflected cross site scripting and open redirect when an attacker can get...
CVE-2021-35959
- EPSS 0.3%
- Veröffentlicht 30.06.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:50
In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.
CVE-2021-33507
- EPSS 0.29%
- Veröffentlicht 21.05.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:58
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.
CVE-2021-33508
- EPSS 0.27%
- Veröffentlicht 21.05.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:58
Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item.
CVE-2021-33509
- EPSS 0.98%
- Veröffentlicht 21.05.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:58
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.
CVE-2021-33510
- EPSS 0.12%
- Veröffentlicht 21.05.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:59
Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file.