Vulnerability index

Browse CVEs

87 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Plone MEDIUM 6.1
CVE-2020-7936

An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, wh…

Fix: after 5.2.1
Fix from $1,600 2020-01-23
Plone MEDIUM 5.4
CVE-2020-7937

An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed whe…

Fix: after 5.2.1
Fix from $1,600 2020-01-23
Plone MEDIUM 6.1
CVE-2013-7062

Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x through 3.3.6, 4.0.x through 4.0.9, 4.1.x through 4.1.6, 4.2.x th…

Fix: after 4.3.2
Fix from $1,600 2020-01-02
Plone MEDIUM 6.1
CVE-2017-1000484

By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the …

Mitigation only
Fix from $1,600 2018-01-03
Plone MEDIUM 6.5
CVE-2017-1000483

Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the for…

Mitigation only
Fix from $1,600 2018-01-03
Plone MEDIUM 6.1
CVE-2017-1000481

When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. Aft…

Mitigation only
Fix from $1,600 2018-01-03
Plone MEDIUM 5.4
CVE-2017-1000482

A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the …

Fix: after 5.0.9
Fix from $1,600 2018-01-03
Plone HIGH 8.8
CVE-2015-7293

Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.

Fix: after 4.3.7
Fix from $1,950 2017-09-25
Plone HIGH 7.5
CVE-2015-7318

Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.

Patch available
Fix from $1,950 2017-09-25
Plone MEDIUM 6.1
CVE-2015-7316

Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x before 4…

Patch available
Fix from $1,600 2017-09-25
Plone MEDIUM 5.9
CVE-2015-7315

Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to…

Patch available
Fix from $1,600 2017-09-25
Plone MEDIUM 6.1
CVE-2016-7138

Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3…

Patch available
Fix from $1,600 2017-03-07
Plone MEDIUM 6.1
CVE-2016-7139

Cross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 …

Patch available
Fix from $1,600 2017-03-07
Plone MEDIUM 6.1
CVE-2016-7140

Multiple cross-site scripting (XSS) vulnerabilities in the ZMI page in Zope2 in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.…

Patch available
Fix from $1,600 2017-03-07
Plone MEDIUM 6.1
CVE-2016-7136

z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GE…

Patch available
Fix from $1,600 2017-03-07
Plone MEDIUM 6.1
CVE-2016-7137

Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect…

Patch available
Fix from $1,600 2017-03-07
Plone HIGH 7.3
CVE-2016-4041

Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webd…

Mitigation only
Fix from $1,950 2017-02-24
Plone MEDIUM 5.3
CVE-2016-4042

Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors.

Mitigation only
Fix from $1,600 2017-02-24
Plone MEDIUM 6.1
CVE-2016-7147

Cross-site scripting (XSS) vulnerability in the manage_findResult component in the search feature in Zope ZMI in Plone before 4.3.12 and 5.x before 5…

Patch available
Fix from $1,600 2017-02-04
Plone MEDIUM 5.0
CVE-2012-5508

The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password re…

Fix: after 4.2.2
Fix from $1,600 2014-11-03
Plone MEDIUM 5.0
CVE-2012-6661

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it e…

Fix: after 4.2.2
Fix from $1,600 2014-11-03
Plone HIGH 8.5
CVE-2012-5493

gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execu…

Fix: after 4.2.2
Fix from $1,950 2014-09-30
Plone MEDIUM 6.5
CVE-2012-5489

The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 bef…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5492

uid_catalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objects via a crafted URL.

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5495

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to "go_back."

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5496

kupu_spellcheck.py in Kupu in Plone before 4.0 allows remote attackers to cause a denial of service (ZServer thread lock) via a crafted URL.

Fix: after 3.3.5
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5497

membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names via a crafted URL.

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5498

queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a crafted req…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5499

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (memory consumption) via a large v…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5501

at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom conten…

Fix: after 4.2.2
Fix from $1,600 2014-09-30