CVE-2017-1000482
- EPSS 0.29%
- Published 03.01.2018 18:29:00
- Last modified 21.11.2024 03:04:49
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
CVE-2017-1000483
- EPSS 0.29%
- Published 03.01.2018 18:29:00
- Last modified 21.11.2024 03:04:50
Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.
CVE-2015-7293
- EPSS 0.33%
- Published 25.09.2017 21:29:00
- Last modified 20.04.2025 01:37:25
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
CVE-2015-7315
- EPSS 0.44%
- Published 25.09.2017 17:29:00
- Last modified 20.04.2025 01:37:25
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administr...
CVE-2015-7316
- EPSS 0.51%
- Published 25.09.2017 17:29:00
- Last modified 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x before 4.3.7, and 5.0rc1.
CVE-2015-7317
- EPSS 0.25%
- Published 25.09.2017 17:29:00
- Last modified 20.04.2025 01:37:25
Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 allows remote authenticated users to edit Kupu settings.
CVE-2015-7318
- EPSS 0.43%
- Published 25.09.2017 17:29:00
- Last modified 20.04.2025 01:37:25
Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.
CVE-2017-5524
- EPSS 0.19%
- Published 23.03.2017 16:59:00
- Last modified 20.04.2025 01:37:25
Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.
CVE-2016-7138
- EPSS 0.49%
- Published 07.03.2017 16:59:01
- Last modified 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVE-2016-7139
- EPSS 0.49%
- Published 07.03.2017 16:59:01
- Last modified 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.