Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-22889 Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted req… Plone Mitigation only Fix from $1,9502024-03-06 HIGH 7.5 CVE-2024-23756 The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangero… Plone No fix yet Fix from $1,9502024-02-08 CRITICAL 9.8 CVE-2024-23054 An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++pl… Plone Docker Official Image Mitigation only Fix from $2,3002024-02-05 MEDIUM 6.1 CVE-2024-23055 An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the H… Plone Docker Official Image No fix yet Fix from $1,6002024-01-25 HIGH 8.8 CVE-2021-33926 An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1… Plone No fix yet Fix from $1,9502023-02-17 MEDIUM 5.4 CVE-2021-29002 A stored cross-site scripting (XSS) vulnerability in Plone CMS 5.2.3 exists in site-controlpanel via the "form.widgets.site_title" parameter. Plone No fix yet Fix from $1,6002021-03-24 MEDIUM 6.1 CVE-2017-1000484 By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the … Plone Mitigation only Fix from $1,6002018-01-03 MEDIUM 6.5 CVE-2017-1000483 Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the for… Plone Mitigation only Fix from $1,6002018-01-03 MEDIUM 6.1 CVE-2017-1000481 When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. Aft… Plone Mitigation only Fix from $1,6002018-01-03 HIGH 7.3 CVE-2016-4041 Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webd… Plone Mitigation only Fix from $1,9502017-02-24 MEDIUM 5.3 CVE-2016-4042 Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors. Plone Mitigation only Fix from $1,6002017-02-24 MEDIUM 5.5 CVE-2013-7061 Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via … Plone Mitigation only Fix from $1,6002014-05-02 MEDIUM 5.0 CVE-2013-7060 Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file obj… Plone Mitigation only Fix from $1,6002014-05-02 HIGH 7.5 CVE-2008-1395 Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for contex… Plone Cms Mitigation only Fix from $1,9502008-03-20 MEDIUM 5.0 CVE-2006-1711 Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword m… Plone Mitigation only Fix from $1,6002006-04-11