Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Plone HIGH 7.5
CVE-2024-22889

Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted req…

Mitigation only
Fix from $1,950 2024-03-06
Plone HIGH 7.5
CVE-2024-23756

The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangero…

No fix yet
Fix from $1,950 2024-02-08
Plone Docker Official Image CRITICAL 9.8
CVE-2024-23054

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++pl…

Mitigation only
Fix from $2,300 2024-02-05
Plone Docker Official Image MEDIUM 6.1
CVE-2024-23055

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the H…

No fix yet
Fix from $1,600 2024-01-25
Plone HIGH 8.8
CVE-2021-33926

An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1…

No fix yet
Fix from $1,950 2023-02-17
Plone MEDIUM 5.4
CVE-2021-29002

A stored cross-site scripting (XSS) vulnerability in Plone CMS 5.2.3 exists in site-controlpanel via the "form.widgets.site_title" parameter.

No fix yet
Fix from $1,600 2021-03-24
Plone MEDIUM 6.1
CVE-2017-1000484

By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the …

Mitigation only
Fix from $1,600 2018-01-03
Plone MEDIUM 6.5
CVE-2017-1000483

Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the for…

Mitigation only
Fix from $1,600 2018-01-03
Plone MEDIUM 6.1
CVE-2017-1000481

When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. Aft…

Mitigation only
Fix from $1,600 2018-01-03
Plone HIGH 7.3
CVE-2016-4041

Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webd…

Mitigation only
Fix from $1,950 2017-02-24
Plone MEDIUM 5.3
CVE-2016-4042

Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors.

Mitigation only
Fix from $1,600 2017-02-24
Plone MEDIUM 5.5
CVE-2013-7061

Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via …

Mitigation only
Fix from $1,600 2014-05-02
Plone MEDIUM 5.0
CVE-2013-7060

Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file obj…

Mitigation only
Fix from $1,600 2014-05-02
Plone Cms HIGH 7.5
CVE-2008-1395

Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for contex…

Mitigation only
Fix from $1,950 2008-03-20
Plone MEDIUM 5.0
CVE-2006-1711

Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword m…

Mitigation only
Fix from $1,600 2006-04-11