<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Plone (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/plone.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/plone-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Plone (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-61668 – Volto is a ReactJS-based frontend for the Plone Content Management System. Versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61668</guid>
    <pubDate>Thu, 02 Oct 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61668</strong></p>
  <p>Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. This issue is fixed in versions 16.34.1, 17.22.2, 18.27.2 and 19.0.0-alpha.6.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58047 – Volto is a React based frontend for the Plone Content Management System. In vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58047</guid>
    <pubDate>Thu, 28 Aug 2025 18:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58047</strong></p>
  <p>Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. The problem has been patched in versions 16.34.0, 17.22.1, 18.24.0, and 19.0.0-a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22889 – Due to incorrect access control in Plone version v6.0.9, remote attackers can vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22889</guid>
    <pubDate>Wed, 06 Mar 2024 00:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22889</strong></p>
  <p>Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23756 – The HTTP PUT and DELETE methods are enabled in the Plone official Docker version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23756</guid>
    <pubDate>Thu, 08 Feb 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23756</strong></p>
  <p>The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23054 – An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23054</guid>
    <pubDate>Mon, 05 Feb 2024 16:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23054</strong></p>
  <p>An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42457 – plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42457</guid>
    <pubDate>Thu, 21 Sep 2023 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42457</strong></p>
  <p>plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and prior to versions 2.0.1 and 3.0.1, when the `++api++` traverser is accidentally used multiple times in a url, handling it takes increasingly longer, making the server less responsive. Patches are available in `plone.rest` 2.0.1 and 3.0.1.  Series 1.x is not affected. As a workar…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37271 – RestrictedPython is a tool that helps to define a subset of the Python language ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37271</guid>
    <pubDate>Tue, 11 Jul 2023 18:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37271</strong></p>
  <p>RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environment. RestrictedPython does not check access to stack frames and their attributes. Stack frames are accessible within at least generators and generator expressions, which are allowed inside RestrictedPython. Prior to versions 6.1 and 5.3, an attacker…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-913</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36814 – Products.CMFCore are the key framework services for the Zope Content Management ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36814</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36814</guid>
    <pubDate>Mon, 03 Jul 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36814</strong></p>
  <p>Products.CMFCore are the key framework services for the Zope Content Management Framework (CMF). The use of Python's marshal module to handle unchecked input in a public method on `PortalFolder` objects can lead to an unauthenticated denial of service and crash situation. The code in question is exposed by all portal software built on top of `Products.CMFCore`, such as Plone. All deployments are…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36814">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33926 – An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33926</guid>
    <pubDate>Fri, 17 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33926</strong></p>
  <p>An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7, 4.3.6, 4.3.5, 4.3.4, 4.3.3, 4.3.20, 4 allows attacker to access sensitive information via the RSS feed protlet.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33511 – Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33511</guid>
    <pubDate>Fri, 21 May 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33511</strong></p>
  <p>Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33509 – Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33509</guid>
    <pubDate>Fri, 21 May 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33509</strong></p>
  <p>Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-28736 – Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28736</guid>
    <pubDate>Wed, 30 Dec 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-28736</strong></p>
  <p>Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-28735 – Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only availabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28735</guid>
    <pubDate>Wed, 30 Dec 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-28735</strong></p>
  <p>Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-28734 – Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only avai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28734</guid>
    <pubDate>Wed, 30 Dec 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-28734</strong></p>
  <p>Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-35190 – The official plone Docker images before version of 4.3.18-alpine (Alpine specifi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35190</guid>
    <pubDate>Thu, 17 Dec 2020 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-35190</strong></p>
  <p>The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7941 – A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7941</guid>
    <pubDate>Thu, 23 Jan 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7941</strong></p>
  <p>A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7940 – Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7940</guid>
    <pubDate>Thu, 23 Jan 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7940</strong></p>
  <p>Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7939 – SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7939</guid>
    <pubDate>Thu, 23 Jan 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7939</strong></p>
  <p>SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7938 – plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7938</guid>
    <pubDate>Thu, 23 Jan 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7938</strong></p>
  <p>plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7293 – Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7293</guid>
    <pubDate>Mon, 25 Sep 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7293</strong></p>
  <p>Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7318 – Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7318</guid>
    <pubDate>Mon, 25 Sep 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7318</strong></p>
  <p>Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-4041 – Plone 4.0 through 5.1a1 does not have security declarations for Dexterity conten...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4041</guid>
    <pubDate>Fri, 24 Feb 2017 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-4041</strong></p>
  <p>Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5493 – gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5493</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5493</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5493</strong></p>
  <p>gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execute arbitrary Python code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5493">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5487 – The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5487</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5487</strong></p>
  <p>The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4030 – The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4030</guid>
    <pubDate>Mon, 10 Oct 2011 10:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4030</strong></p>
  <p>The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-3587 – Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-3587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-3587</guid>
    <pubDate>Mon, 10 Oct 2011 10:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-3587</strong></p>
  <p>Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2528 – Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2528</guid>
    <pubDate>Tue, 19 Jul 2011 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2528</strong></p>
  <p>Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix20110720 for Plone 3.x allows attackers to gain privileges via unspecified vectors, related to a "highly serious vulnerability." NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-0720.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-0720 – Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0720</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0720</guid>
    <pubDate>Thu, 03 Feb 2011 17:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-0720</strong></p>
  <p>Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0720">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-1393 – Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1393</guid>
    <pubDate>Thu, 20 Mar 2008 00:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-1393</strong></p>
  <p>Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1394 – Plone CMS before 3 places a base64 encoded form of the username and password in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1394</guid>
    <pubDate>Thu, 20 Mar 2008 00:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1394</strong></p>
  <p>Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1395 – Plone CMS does not record users' authentication states, and implements the logou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1395</guid>
    <pubDate>Thu, 20 Mar 2008 00:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1395</strong></p>
  <p>Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for context-dependent attackers to reuse a logged-out session.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-5741 – Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5741</guid>
    <pubDate>Wed, 07 Nov 2007 21:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-5741</strong></p>
  <p>Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled objects for the (1) statusmessages or (2) linkintegrity module, which the module unpickles and executes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5741">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
