CVE-2017-1000482
- EPSS 0.29%
- Veröffentlicht 03.01.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:49
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
CVE-2017-1000483
- EPSS 0.29%
- Veröffentlicht 03.01.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:50
Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.
CVE-2015-7293
- EPSS 0.33%
- Veröffentlicht 25.09.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
CVE-2015-7315
- EPSS 0.44%
- Veröffentlicht 25.09.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administr...
CVE-2015-7316
- EPSS 0.51%
- Veröffentlicht 25.09.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x before 4.3.7, and 5.0rc1.
CVE-2015-7317
- EPSS 0.25%
- Veröffentlicht 25.09.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 allows remote authenticated users to edit Kupu settings.
CVE-2015-7318
- EPSS 0.43%
- Veröffentlicht 25.09.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.
CVE-2017-5524
- EPSS 0.19%
- Veröffentlicht 23.03.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.
CVE-2016-7138
- EPSS 0.49%
- Veröffentlicht 07.03.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVE-2016-7139
- EPSS 0.49%
- Veröffentlicht 07.03.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.