Plone

Plone

103 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.47%
  • Published 06.03.2024 00:15:52
  • Last modified 21.01.2025 16:53:16

Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.

Exploit
  • EPSS 0.22%
  • Published 08.02.2024 21:15:08
  • Last modified 15.05.2025 20:15:44

The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.

  • EPSS 0.05%
  • Published 18.01.2024 13:15:09
  • Last modified 21.11.2024 08:47:06

A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.

Exploit
  • EPSS 0.21%
  • Published 17.02.2023 18:15:11
  • Last modified 19.03.2025 15:15:36

An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1...

  • EPSS 0.32%
  • Published 28.01.2022 22:15:17
  • Last modified 05.05.2025 17:17:57

Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products.ATContentTypes prior to version 3.0.6 are vulnerable to reflected cross site scripting and open redirect when an attacker can get...

  • EPSS 0.3%
  • Published 30.06.2021 01:15:07
  • Last modified 21.11.2024 06:12:50

In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.

  • EPSS 0.29%
  • Published 21.05.2021 22:15:08
  • Last modified 21.11.2024 06:08:58

Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.

  • EPSS 0.27%
  • Published 21.05.2021 22:15:08
  • Last modified 21.11.2024 06:08:58

Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item.

  • EPSS 0.98%
  • Published 21.05.2021 22:15:08
  • Last modified 21.11.2024 06:08:58

Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.

  • EPSS 0.12%
  • Published 21.05.2021 22:15:08
  • Last modified 21.11.2024 06:08:59

Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file.