<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Plone</title>
  <link>https://cvedaily.com/pages/tags/plone.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/plone.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Plone</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-28413 – Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28413</guid>
    <pubDate>Thu, 05 Mar 2026 21:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28413</strong></p>
  <p>Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redirect to an external website after login. This issue has been patched in versions 2.1.0, 3.1.0, and 4.0.0.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61668 – Volto is a ReactJS-based frontend for the Plone Content Management System. Versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61668</guid>
    <pubDate>Thu, 02 Oct 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61668</strong></p>
  <p>Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. This issue is fixed in versions 16.34.1, 17.22.2, 18.27.2 and 19.0.0-alpha.6.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58047 – Volto is a React based frontend for the Plone Content Management System. In vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58047</guid>
    <pubDate>Thu, 28 Aug 2025 18:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58047</strong></p>
  <p>Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. The problem has been patched in versions 16.34.0, 17.22.1, 18.24.0, and 19.0.0-a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22889 – Due to incorrect access control in Plone version v6.0.9, remote attackers can vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22889</guid>
    <pubDate>Wed, 06 Mar 2024 00:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22889</strong></p>
  <p>Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23756 – The HTTP PUT and DELETE methods are enabled in the Plone official Docker version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23756</guid>
    <pubDate>Thu, 08 Feb 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23756</strong></p>
  <p>The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23054 – An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23054</guid>
    <pubDate>Mon, 05 Feb 2024 16:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23054</strong></p>
  <p>An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23055 – An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23055</guid>
    <pubDate>Thu, 25 Jan 2024 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23055</strong></p>
  <p>An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0669 – A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0669</guid>
    <pubDate>Thu, 18 Jan 2024 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0669</strong></p>
  <p>A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42457 – plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42457</guid>
    <pubDate>Thu, 21 Sep 2023 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42457</strong></p>
  <p>plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and prior to versions 2.0.1 and 3.0.1, when the `++api++` traverser is accidentally used multiple times in a url, handling it takes increasingly longer, making the server less responsive. Patches are available in `plone.rest` 2.0.1 and 3.0.1.  Series 1.x is not affected. As a workar…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-41048 – plone.namedfile allows users to handle `File` and `Image` fields targeting, but ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41048</guid>
    <pubDate>Thu, 21 Sep 2023 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-41048</strong></p>
  <p>plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity content. Prior to versions 5.6.1, 6.0.3, 6.1.3, and 6.2.1, there is a stored cross site scripting vulnerability for SVG images. A security hotfix from 2021 already partially fixed this by making sure SVG images are always downloaded instead of shown inline. But the same problem still…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37271 – RestrictedPython is a tool that helps to define a subset of the Python language ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37271</guid>
    <pubDate>Tue, 11 Jul 2023 18:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37271</strong></p>
  <p>RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environment. RestrictedPython does not check access to stack frames and their attributes. Stack frames are accessible within at least generators and generator expressions, which are allowed inside RestrictedPython. Prior to versions 6.1 and 5.3, an attacker…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-913</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36814 – Products.CMFCore are the key framework services for the Zope Content Management ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36814</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36814</guid>
    <pubDate>Mon, 03 Jul 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36814</strong></p>
  <p>Products.CMFCore are the key framework services for the Zope Content Management Framework (CMF). The use of Python's marshal module to handle unchecked input in a public method on `PortalFolder` objects can lead to an unauthenticated denial of service and crash situation. The code in question is exposed by all portal software built on top of `Products.CMFCore`, such as Plone. All deployments are…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36814">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33926 – An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33926</guid>
    <pubDate>Fri, 17 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33926</strong></p>
  <p>An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7, 4.3.6, 4.3.5, 4.3.4, 4.3.3, 4.3.20, 4 allows attacker to access sensitive information via the RSS feed protlet.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24740 – Volto is a ReactJS-based frontend for the Plone Content Management System. Betwe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24740</guid>
    <pubDate>Mon, 14 Mar 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24740</strong></p>
  <p>Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-alpha.0, a user could have their authentication cookie replaced with an authentication cookie from another user, effectively giving them control of the other user's account and privileges. This occurs when using an outdated version of the `react-cookie` library and a server is und…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23599 – Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23599</guid>
    <pubDate>Fri, 28 Jan 2022 22:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23599</strong></p>
  <p>Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products.ATContentTypes prior to version 3.0.6 are vulnerable to reflected cross site scripting and open redirect when an attacker can get a compromised version of the image_view_fullscreen page in a cache, for example in Varnish. The technique is known as cache poisoning. Any later vis…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32806 – Products.isurlinportal is a replacement for isURLInPortal method in Plone. Versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32806</guid>
    <pubDate>Mon, 02 Aug 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32806</strong></p>
  <p>Products.isurlinportal is a replacement for isURLInPortal method in Plone. Versions of Products.isurlinportal prior to 1.2.0 have an Open Redirect vulnerability. Various parts of Plone use the 'is url in portal' check for security, mostly to see if it is safe to redirect to a url. A url like `https://example.org` is not in the portal. The url `https:example.org` without slashes is considered to b…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-35959 – In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35959</guid>
    <pubDate>Wed, 30 Jun 2021 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-35959</strong></p>
  <p>In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-33513 – Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33513</guid>
    <pubDate>Fri, 21 May 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-33513</strong></p>
  <p>Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-33512 – Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33512</guid>
    <pubDate>Fri, 21 May 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-33512</strong></p>
  <p>Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33511 – Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33511</guid>
    <pubDate>Fri, 21 May 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33511</strong></p>
  <p>Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-33510 – Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33510</guid>
    <pubDate>Fri, 21 May 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-33510</strong></p>
  <p>Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33509 – Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33509</guid>
    <pubDate>Fri, 21 May 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33509</strong></p>
  <p>Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-33508 – Plone through 5.2.4 allows XSS via a full name that is mishandled during renderi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33508</guid>
    <pubDate>Fri, 21 May 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-33508</strong></p>
  <p>Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-33507 – Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33507</guid>
    <pubDate>Fri, 21 May 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-33507</strong></p>
  <p>Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3313 – Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3313</guid>
    <pubDate>Thu, 20 May 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3313</strong></p>
  <p>Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and the file upload functionality. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser and allows an attacker to execute JavaScript in the context of the victim's browser if the victim opens a…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-29002 – A stored cross-site scripting (XSS) vulnerability in Plone CMS 5.2.3 exists in s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29002</guid>
    <pubDate>Wed, 24 Mar 2021 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-29002</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability in Plone CMS 5.2.3 exists in site-controlpanel via the "form.widgets.site_title" parameter.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29002">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-28736 – Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28736</guid>
    <pubDate>Wed, 30 Dec 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-28736</strong></p>
  <p>Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-28735 – Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only availabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28735</guid>
    <pubDate>Wed, 30 Dec 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-28735</strong></p>
  <p>Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-28734 – Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only avai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28734</guid>
    <pubDate>Wed, 30 Dec 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-28734</strong></p>
  <p>Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-35190 – The official plone Docker images before version of 4.3.18-alpine (Alpine specifi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35190</guid>
    <pubDate>Thu, 17 Dec 2020 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-35190</strong></p>
  <p>The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7941 – A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7941</guid>
    <pubDate>Thu, 23 Jan 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7941</strong></p>
  <p>A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7940 – Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7940</guid>
    <pubDate>Thu, 23 Jan 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7940</strong></p>
  <p>Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7939 – SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7939</guid>
    <pubDate>Thu, 23 Jan 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7939</strong></p>
  <p>SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7938 – plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7938</guid>
    <pubDate>Thu, 23 Jan 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7938</strong></p>
  <p>plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-7937 – An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7937</guid>
    <pubDate>Thu, 23 Jan 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-7937</strong></p>
  <p>An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-7936 – An open redirect on the login form (and possibly other places) in Plone 4.0 thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7936</guid>
    <pubDate>Thu, 23 Jan 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-7936</strong></p>
  <p>An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-7062 – Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7062</guid>
    <pubDate>Thu, 02 Jan 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-7062</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x through 3.3.6, 4.0.x through 4.0.9, 4.1.x through 4.1.6, 4.2.x through 4.2.7, and 4.3 through 4.3.2, allow remote attackers to inject arbitrary web script or HTML via unspecified input in the (1) browser_id_manager or (2) OFS.Image method.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-1000484 – By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000484</guid>
    <pubDate>Wed, 03 Jan 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-1000484</strong></p>
  <p>By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the attacker could more easily link directly to his own website instead. But in combination with another attack, you could be sent to the Plone login form and login, then get redirected to the specific url, and then get a second redirect to the attacker…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-1000483 – Accessing private content via str.format in through-the-web templates and script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000483</guid>
    <pubDate>Wed, 03 Jan 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-1000483</strong></p>
  <p>Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-1000482 – A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page prop...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000482</guid>
    <pubDate>Wed, 03 Jan 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-1000482</strong></p>
  <p>A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-1000481 – When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000481</guid>
    <pubDate>Wed, 03 Jan 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-1000481</strong></p>
  <p>When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might try to abuse this by letting you click on a specially crafted link. You would login, and get redirected to the site of the attacker, letting you think that you a…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7293 – Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7293</guid>
    <pubDate>Mon, 25 Sep 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7293</strong></p>
  <p>Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7318 – Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7318</guid>
    <pubDate>Mon, 25 Sep 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7318</strong></p>
  <p>Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-7316 – Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7316</guid>
    <pubDate>Mon, 25 Sep 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-7316</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x before 4.3.7, and 5.0rc1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-7315 – Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7315</guid>
    <pubDate>Mon, 25 Sep 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-7315</strong></p>
  <p>Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-5524 – Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5524</guid>
    <pubDate>Thu, 23 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-5524</strong></p>
  <p>Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-7140 – Multiple cross-site scripting (XSS) vulnerabilities in the ZMI page in Zope2 in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7140</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-7140</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in the ZMI page in Zope2 in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-7139 – Cross-site scripting (XSS) vulnerability in an unspecified page template in Plon...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7139</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-7139</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-7138 – Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7138</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-7138</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-7137 – Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7137</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-7137</strong></p>
  <p>Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.A…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-7136 – z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7136</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-7136</strong></p>
  <p>z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GET request.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-7135 – Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7135</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-7135</strong></p>
  <p>Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a .. (dot dot) in the path parameter in a getFile action to Plone/++theme++barceloneta/@@plone.resourceeditor.filemanager-actions.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-4043 – Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4043</guid>
    <pubDate>Fri, 24 Feb 2017 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-4043</strong></p>
  <p>Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-4042 – Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4042</guid>
    <pubDate>Fri, 24 Feb 2017 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-4042</strong></p>
  <p>Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-4041 – Plone 4.0 through 5.1a1 does not have security declarations for Dexterity conten...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4041</guid>
    <pubDate>Fri, 24 Feb 2017 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-4041</strong></p>
  <p>Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-7147 – Cross-site scripting (XSS) vulnerability in the manage_findResult component in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7147</guid>
    <pubDate>Sat, 04 Feb 2017 05:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-7147</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the manage_findResult component in the search feature in Zope ZMI in Plone before 4.3.12 and 5.x before 5.0.7 allows remote attackers to inject arbitrary web script or HTML via vectors involving double quotes, as demonstrated by the obj_ids:tokens parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7140.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-6661 – Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6661</guid>
    <pubDate>Mon, 03 Nov 2014 22:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-6661</strong></p>
  <p>Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors.  NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5508 – The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5508</guid>
    <pubDate>Mon, 03 Nov 2014 22:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5508</strong></p>
  <p>The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password resets via unspecified vectors.  NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6661 was assigned for the PRNG reseeding issue in Zope.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5500 – The batch id change script (renameObjectsByPaths.py) in Plone before 4.2.3 and 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5500</guid>
    <pubDate>Mon, 03 Nov 2014 22:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5500</strong></p>
  <p>The batch id change script (renameObjectsByPaths.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to change the titles of content items by leveraging a valid CSRF token in a crafted request.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5507 – AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5507</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5507</strong></p>
  <p>AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5506 – python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5506</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5506</strong></p>
  <p>python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (infinite loop) via an RSS feed request for a folder the user does not have permission to access.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5505 – atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5505</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5505</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5505</strong></p>
  <p>atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a request for a view without a name.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5505">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5504 – Cross-site scripting (XSS) vulnerability in widget_traversal.py in Plone before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5504</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5504</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in widget_traversal.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5503 – ftp.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5503</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5503</strong></p>
  <p>ftp.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read hidden folder contents via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2012-5502 – Cross-site scripting (XSS) vulnerability in safe_html.py in Plone before 4.2.3 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5502</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2012-5502</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in safe_html.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with permissions to edit content to inject arbitrary web script or HTML via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5502">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5501 – at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5501</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5501</strong></p>
  <p>at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom content types via a crafted URL.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5499 – python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5499</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5499</strong></p>
  <p>python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (memory consumption) via a large value, related to formatColumns.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5498 – queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5498</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5498</strong></p>
  <p>queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a crafted request to a collection.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5497 – membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5497</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5497</strong></p>
  <p>membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names via a crafted URL.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5496 – kupu_spellcheck.py in Kupu in Plone before 4.0 allows remote attackers to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5496</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5496</strong></p>
  <p>kupu_spellcheck.py in Kupu in Plone before 4.0 allows remote attackers to cause a denial of service (ZServer thread lock) via a crafted URL.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5495 – python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5495</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5495</strong></p>
  <p>python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to "go_back."</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5494 – Cross-site scripting (XSS) vulnerability in python_scripts.py in Plone before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5494</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5494</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5494</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "{u,}translate."</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5494">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5493 – gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5493</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5493</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5493</strong></p>
  <p>gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execute arbitrary Python code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5493">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5492 – uid_catalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5492</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5492</strong></p>
  <p>uid_catalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objects via a crafted URL.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5491 – z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5491</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5491</strong></p>
  <p>z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field values by leveraging knowledge of the form location and the element id.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5490 – Cross-site scripting (XSS) vulnerability in kssdevel.py in Plone before 4.2.3 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5490</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5490</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in kssdevel.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5489 – The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5489</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5489</strong></p>
  <p>The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5488 – python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5488</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5488</strong></p>
  <p>python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5487 – The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5487</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5487</strong></p>
  <p>The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5486 – ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5486</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5486</strong></p>
  <p>ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5485 – registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5485</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5485</guid>
    <pubDate>Tue, 30 Sep 2014 14:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5485</strong></p>
  <p>registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5485">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-7061 – Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote admini...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7061</guid>
    <pubDate>Fri, 02 May 2014 14:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-7061</strong></p>
  <p>Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-7060 – Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7060</guid>
    <pubDate>Fri, 02 May 2014 14:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-7060</strong></p>
  <p>Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4198 – mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4198</guid>
    <pubDate>Tue, 11 Mar 2014 19:37:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4198</strong></p>
  <p>mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2013-4199 – (1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4199</guid>
    <pubDate>Tue, 11 Mar 2014 19:37:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2013-4199</strong></p>
  <p>(1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users to cause a denial of service (resource consumption) via a large zip archive, which is expanded (decompressed).</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4197 – member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4197</guid>
    <pubDate>Tue, 11 Mar 2014 19:37:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4197</strong></p>
  <p>member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4195 – Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4195</guid>
    <pubDate>Tue, 11 Mar 2014 19:37:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4195</strong></p>
  <p>Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4196 – The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4196</guid>
    <pubDate>Tue, 11 Mar 2014 19:37:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4196</strong></p>
  <p>The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restrict access to internal methods, which allows remote attackers to obtain sensitive information via a crafted request.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4193 – typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4193</guid>
    <pubDate>Tue, 11 Mar 2014 19:37:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4193</strong></p>
  <p>typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4194 – The WYSIWYG component (wysiwyg.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4194</guid>
    <pubDate>Tue, 11 Mar 2014 19:37:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4194</strong></p>
  <p>The WYSIWYG component (wysiwyg.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers to obtain sensitive information via a crafted URL, which reveals the installation path in an error message.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4192 – sendto.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4192</guid>
    <pubDate>Tue, 11 Mar 2014 19:37:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4192</strong></p>
  <p>sendto.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to spoof emails via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4191 – zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4191</guid>
    <pubDate>Tue, 11 Mar 2014 19:37:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4191</strong></p>
  <p>zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restrictions when including content in a zip archive, which allows remote attackers to obtain sensitive information by reading a generated archive.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4189 – Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) tr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4189</guid>
    <pubDate>Tue, 11 Mar 2014 19:37:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4189</strong></p>
  <p>Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users with administrator access to a subtree to access nodes above the subtree via unknown vectors.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4190 – Multiple cross-site scripting (XSS) vulnerabilities in (1) spamProtect.py, (2) p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4190</guid>
    <pubDate>Tue, 11 Mar 2014 19:37:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4190</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in (1) spamProtect.py, (2) pts.py, and (3) request.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4188 – traverser.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4188</guid>
    <pubDate>Tue, 11 Mar 2014 19:37:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4188</strong></p>
  <p>traverser.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers with administrator privileges to cause a denial of service (infinite loop and resource consumption) via unspecified vectors related to "retrieving information for certain resources."</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4200 – The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4200</guid>
    <pubDate>Tue, 21 Jan 2014 16:06:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4200</strong></p>
  <p>The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows remote attackers to bypass the allow_external_login_sites filtering property,  redirect users to arbitrary web sites, and conduct phishing attacks via a space before a URL in the "next" parameter to a…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4462 – Plone 4.1.3 and earlier computes hash values for form parameters without restric...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4462</guid>
    <pubDate>Fri, 30 Dec 2011 01:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4462</strong></p>
  <p>Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4030 – The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4030</guid>
    <pubDate>Mon, 10 Oct 2011 10:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4030</strong></p>
  <p>The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-3587 – Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-3587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-3587</guid>
    <pubDate>Mon, 10 Oct 2011 10:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-3587</strong></p>
  <p>Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-1340 – Cross-site scripting (XSS) vulnerability in skins/plone_templates/default_error_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1340</guid>
    <pubDate>Fri, 05 Aug 2011 21:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-1340</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in skins/plone_templates/default_error_message.pt in Plone before 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the type_name parameter to Members/ipa/createObject.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1340">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
