Перейти к содержимому
Noroxi

Записи plone

116 опубликованных записей вендора plone.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 0,9 %
Pre-auth RCE
7
С записью об исправлении
92,2 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

116 записей
  • CVE-2011-3587
    60На этой неделе

    Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attacke

    КритическаяCVSS 9,3Готовый эксплойтEPSS 78 %

    plone · plone10 окт. 2011 г.

  • CVE-2008-1393
    41В плане

    Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    plone · plone cms19 мар. 2008 г.

  • CVE-2020-7941
    40В плане

    A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needi

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    plone · plone23 янв. 2020 г.

  • CVE-2020-35190
    40В плане

    The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    plone · plone16 дек. 2020 г.

  • CVE-2021-33509
    40В плане

    Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform

    КритическаяCVSS 9,9Эксплойта нетEPSS 2 %

    plone · plone21 мая 2021 г.

  • CVE-2024-23054
    39Наблюдать

    An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package liste

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    plone · plone docker official image5 февр. 2024 г.

  • CVE-2011-4030
    38Наблюдать

    The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from bein

    КритическаяCVSS 9,3Эксплойта нетEPSS 2 %

    plone · cmfeditions10 окт. 2011 г.

  • CVE-2015-7293
    36Наблюдать

    Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.

    ВысокаяCVSS 8,8Proof of conceptEPSS 3 %

    plone · plone25 сент. 2017 г.

  • CVE-2021-32633
    36Наблюдать

    Remote Code Execution via traversal in TAL expressions

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    zope · zope21 мая 2021 г.

  • CVE-2012-5487
    35Наблюдать

    The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certai

    ВысокаяCVSS 8,5Эксплойта нетEPSS 2 %

    plone · plone30 сент. 2014 г.

  • CVE-2012-5493
    35Наблюдать

    gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox

    ВысокаяCVSS 8,5Эксплойта нетEPSS 2 %

    plone · plone30 сент. 2014 г.

  • CVE-2020-7938
    35Наблюдать

    plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    plone · plone23 янв. 2020 г.

  • CVE-2020-28735
    35Наблюдать

    Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    plone · plone30 дек. 2020 г.

  • CVE-2020-28736
    35Наблюдать

    Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (there

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    plone · plone30 дек. 2020 г.

  • CVE-2020-28734
    35Наблюдать

    Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    plone · plone30 дек. 2020 г.

  • CVE-2020-7939
    35Наблюдать

    SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    plone · plone23 янв. 2020 г.

  • CVE-2021-33926
    35Наблюдать

    An issue in Plone CMS v.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    plone · plone17 февр. 2023 г.

  • CVE-2011-0720
    31Наблюдать

    Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    plone · plone3 февр. 2011 г.

  • CVE-2007-5741
    31Наблюдать

    Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled o

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    plone · plone7 нояб. 2007 г.

  • CVE-2011-2528
    31Наблюдать

    Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) Plone

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    plone · plone hotfix 2011072019 июл. 2011 г.

  • CVE-2015-7318
    31Наблюдать

    Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    plone · plone25 сент. 2017 г.

  • CVE-2008-1394
    30Наблюдать

    Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    plone · plone cms19 мар. 2008 г.

  • CVE-2008-1395
    30Наблюдать

    Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier f

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    plone · plone cms19 мар. 2008 г.

  • CVE-2020-7940
    30Наблюдать

    Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    plone · plone23 янв. 2020 г.

  • CVE-2021-33511
    30Наблюдать

    Plone though 5.2.4 allows SSRF via the lxml parser.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    plone · plone21 мая 2021 г.