plone records
116 published records for vendor plone.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.9%
- Pre-auth RCE
- 7
- With a fix record
- 92.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')28
- CWE-264 Permissions, Privileges, and Access Controls15
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor9
- CWE-20 Improper Input Validation6
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')6
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
The weakness classes this vendor ships most often: where to look.
CWEAll records
116 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2011-3587Weaponized | Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackeplone · plone | Critical9.3 | — | 78.1% | Oct 10, 2011 |
41Plan | CVE-2008-1393No exploit | Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the adminplone · plone cms · CWE-255 | Critical10.0 | — | 2.9% | Mar 19, 2008 |
40Plan | CVE-2020-7941No exploit | A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without neediplone · plone | Critical9.8 | — | 2.3% | Jan 23, 2020 |
40Plan | CVE-2020-35190No exploit | The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user.plone · plone · CWE-306 | Critical9.8 | — | 2.2% | Dec 16, 2020 |
40Plan | CVE-2021-33509No exploit | Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transformplone · plone · CWE-732 | Critical9.9 | — | 2.0% | May 21, 2021 |
39Monitor | CVE-2024-23054No exploit | An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listeplone · plone docker official image · CWE-427 | Critical9.8 | — | 1.3% | Feb 5, 2024 |
38Monitor | CVE-2011-4030No exploit | The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from beinplone · cmfeditions · CWE-264 | Critical9.3 | — | 2.0% | Oct 10, 2011 |
36Monitor | CVE-2015-7293Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.plone · plone · CWE-352 | High8.8 | — | 3.0% | Sep 25, 2017 |
36Monitor | CVE-2021-32633No exploit | Remote Code Execution via traversal in TAL expressionszope · zope · CWE-22 | High8.8 | — | 1.9% | May 21, 2021 |
35Monitor | CVE-2012-5487No exploit | The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certaiplone · plone · CWE-264 | High8.5 | — | 1.7% | Sep 30, 2014 |
35Monitor | CVE-2012-5493No exploit | gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox plone · plone · CWE-94 | High8.5 | — | 1.7% | Sep 30, 2014 |
35Monitor | CVE-2020-7938No exploit | plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.plone · plone | High8.8 | — | 1.5% | Jan 23, 2020 |
35Monitor | CVE-2020-28735No exploit | Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).plone · plone · CWE-918 | High8.8 | — | 1.5% | Dec 30, 2020 |
35Monitor | CVE-2020-28736No exploit | Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (thereplone · plone · CWE-611 | High8.8 | — | 1.5% | Dec 30, 2020 |
35Monitor | CVE-2020-28734No exploit | Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.plone · plone · CWE-611 | High8.8 | — | 1.5% | Dec 30, 2020 |
35Monitor | CVE-2020-7939No exploit | SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries.plone · plone · CWE-89 | High8.8 | — | 1.2% | Jan 23, 2020 |
35Monitor | CVE-2021-33926No exploit | An issue in Plone CMS v.plone · plone · CWE-918 | High8.8 | — | 1.0% | Feb 17, 2023 |
31Monitor | CVE-2011-0720No exploit | Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain aplone · plone | High7.5 | — | 3.2% | Feb 3, 2011 |
31Monitor | CVE-2007-5741No exploit | Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled oplone · plone · CWE-94 | High7.5 | — | 2.2% | Nov 7, 2007 |
31Monitor | CVE-2011-2528No exploit | Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) Ploneplone · plone hotfix 20110720 | High7.5 | — | 2.0% | Jul 19, 2011 |
31Monitor | CVE-2015-7318No exploit | Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.plone · plone · CWE-20 | High7.5 | — | 1.7% | Sep 25, 2017 |
30Monitor | CVE-2008-1394No exploit | Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easierplone · plone cms · CWE-255 | High7.5 | — | 1.4% | Mar 19, 2008 |
30Monitor | CVE-2008-1395No exploit | Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier fplone · plone cms · CWE-287 | High7.5 | — | 1.3% | Mar 19, 2008 |
30Monitor | CVE-2020-7940No exploit | Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.plone · plone · CWE-521 | High7.5 | — | 1.3% | Jan 23, 2020 |
30Monitor | CVE-2021-33511No exploit | Plone though 5.2.4 allows SSRF via the lxml parser.plone · plone · CWE-918 | High7.5 | — | 1.2% | May 21, 2021 |
- CVE-2011-358760This week
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attacke
CriticalCVSS 9.3WeaponizedEPSS 78%plone · ploneOct 10, 2011
- CVE-2008-139341Plan
Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin
CriticalCVSS 10.0No exploitEPSS 3%plone · plone cmsMar 19, 2008
- CVE-2020-794140Plan
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needi
CriticalCVSS 9.8No exploitEPSS 2%plone · ploneJan 23, 2020
- CVE-2020-3519040Plan
The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 2%plone · ploneDec 16, 2020
- CVE-2021-3350940Plan
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform
CriticalCVSS 9.9No exploitEPSS 2%plone · ploneMay 21, 2021
- CVE-2024-2305439Monitor
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package liste
CriticalCVSS 9.8No exploitEPSS 1%plone · plone docker official imageFeb 5, 2024
- CVE-2011-403038Monitor
The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from bein
CriticalCVSS 9.3No exploitEPSS 2%plone · cmfeditionsOct 10, 2011
- CVE-2015-729336Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
HighCVSS 8.8Proof of conceptEPSS 3%plone · ploneSep 25, 2017
- CVE-2021-3263336Monitor
Remote Code Execution via traversal in TAL expressions
HighCVSS 8.8No exploitEPSS 2%zope · zopeMay 21, 2021
- CVE-2012-548735Monitor
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certai
HighCVSS 8.5No exploitEPSS 2%plone · ploneSep 30, 2014
- CVE-2012-549335Monitor
gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox
HighCVSS 8.5No exploitEPSS 2%plone · ploneSep 30, 2014
- CVE-2020-793835Monitor
plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.
HighCVSS 8.8No exploitEPSS 1%plone · ploneJan 23, 2020
- CVE-2020-2873535Monitor
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
HighCVSS 8.8No exploitEPSS 1%plone · ploneDec 30, 2020
- CVE-2020-2873635Monitor
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (there
HighCVSS 8.8No exploitEPSS 1%plone · ploneDec 30, 2020
- CVE-2020-2873435Monitor
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
HighCVSS 8.8No exploitEPSS 1%plone · ploneDec 30, 2020
- CVE-2020-793935Monitor
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries.
HighCVSS 8.8No exploitEPSS 1%plone · ploneJan 23, 2020
- CVE-2021-3392635Monitor
An issue in Plone CMS v.
HighCVSS 8.8No exploitEPSS 1%plone · ploneFeb 17, 2023
- CVE-2011-072031Monitor
Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain a
HighCVSS 7.5No exploitEPSS 3%plone · ploneFeb 3, 2011
- CVE-2007-574131Monitor
Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled o
HighCVSS 7.5No exploitEPSS 2%plone · ploneNov 7, 2007
- CVE-2011-252831Monitor
Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) Plone
HighCVSS 7.5No exploitEPSS 2%plone · plone hotfix 20110720Jul 19, 2011
- CVE-2015-731831Monitor
Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.
HighCVSS 7.5No exploitEPSS 2%plone · ploneSep 25, 2017
- CVE-2008-139430Monitor
Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier
HighCVSS 7.5No exploitEPSS 1%plone · plone cmsMar 19, 2008
- CVE-2008-139530Monitor
Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier f
HighCVSS 7.5No exploitEPSS 1%plone · plone cmsMar 19, 2008
- CVE-2020-794030Monitor
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
HighCVSS 7.5No exploitEPSS 1%plone · ploneJan 23, 2020
- CVE-2021-3351130Monitor
Plone though 5.2.4 allows SSRF via the lxml parser.
HighCVSS 7.5No exploitEPSS 1%plone · ploneMay 21, 2021