Записи plone
116 опубликованных записей вендора plone.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,9 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 92,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')28
- CWE-264 Permissions, Privileges, and Access Controls15
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor9
- CWE-20 Improper Input Validation6
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')6
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
116 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2011-3587Готовый эксплойт | Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackeplone · plone | Критическая9,3 | — | 78,1 % | 10 окт. 2011 г. |
41В плане | CVE-2008-1393Эксплойта нет | Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the adminplone · plone cms · CWE-255 | Критическая10,0 | — | 2,9 % | 19 мар. 2008 г. |
40В плане | CVE-2020-7941Эксплойта нет | A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without neediplone · plone | Критическая9,8 | — | 2,3 % | 23 янв. 2020 г. |
40В плане | CVE-2020-35190Эксплойта нет | The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user.plone · plone · CWE-306 | Критическая9,8 | — | 2,2 % | 16 дек. 2020 г. |
40В плане | CVE-2021-33509Эксплойта нет | Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transformplone · plone · CWE-732 | Критическая9,9 | — | 2,0 % | 21 мая 2021 г. |
39Наблюдать | CVE-2024-23054Эксплойта нет | An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listeplone · plone docker official image · CWE-427 | Критическая9,8 | — | 1,3 % | 5 февр. 2024 г. |
38Наблюдать | CVE-2011-4030Эксплойта нет | The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from beinplone · cmfeditions · CWE-264 | Критическая9,3 | — | 2,0 % | 10 окт. 2011 г. |
36Наблюдать | CVE-2015-7293Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.plone · plone · CWE-352 | Высокая8,8 | — | 3,0 % | 25 сент. 2017 г. |
36Наблюдать | CVE-2021-32633Эксплойта нет | Remote Code Execution via traversal in TAL expressionszope · zope · CWE-22 | Высокая8,8 | — | 1,9 % | 21 мая 2021 г. |
35Наблюдать | CVE-2012-5487Эксплойта нет | The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certaiplone · plone · CWE-264 | Высокая8,5 | — | 1,7 % | 30 сент. 2014 г. |
35Наблюдать | CVE-2012-5493Эксплойта нет | gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox plone · plone · CWE-94 | Высокая8,5 | — | 1,7 % | 30 сент. 2014 г. |
35Наблюдать | CVE-2020-7938Эксплойта нет | plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.plone · plone | Высокая8,8 | — | 1,5 % | 23 янв. 2020 г. |
35Наблюдать | CVE-2020-28735Эксплойта нет | Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).plone · plone · CWE-918 | Высокая8,8 | — | 1,5 % | 30 дек. 2020 г. |
35Наблюдать | CVE-2020-28736Эксплойта нет | Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (thereplone · plone · CWE-611 | Высокая8,8 | — | 1,5 % | 30 дек. 2020 г. |
35Наблюдать | CVE-2020-28734Эксплойта нет | Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.plone · plone · CWE-611 | Высокая8,8 | — | 1,5 % | 30 дек. 2020 г. |
35Наблюдать | CVE-2020-7939Эксплойта нет | SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries.plone · plone · CWE-89 | Высокая8,8 | — | 1,2 % | 23 янв. 2020 г. |
35Наблюдать | CVE-2021-33926Эксплойта нет | An issue in Plone CMS v.plone · plone · CWE-918 | Высокая8,8 | — | 1,0 % | 17 февр. 2023 г. |
31Наблюдать | CVE-2011-0720Эксплойта нет | Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain aplone · plone | Высокая7,5 | — | 3,2 % | 3 февр. 2011 г. |
31Наблюдать | CVE-2007-5741Эксплойта нет | Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled oplone · plone · CWE-94 | Высокая7,5 | — | 2,2 % | 7 нояб. 2007 г. |
31Наблюдать | CVE-2011-2528Эксплойта нет | Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) Ploneplone · plone hotfix 20110720 | Высокая7,5 | — | 2,0 % | 19 июл. 2011 г. |
31Наблюдать | CVE-2015-7318Эксплойта нет | Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.plone · plone · CWE-20 | Высокая7,5 | — | 1,7 % | 25 сент. 2017 г. |
30Наблюдать | CVE-2008-1394Эксплойта нет | Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easierplone · plone cms · CWE-255 | Высокая7,5 | — | 1,4 % | 19 мар. 2008 г. |
30Наблюдать | CVE-2008-1395Эксплойта нет | Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier fplone · plone cms · CWE-287 | Высокая7,5 | — | 1,3 % | 19 мар. 2008 г. |
30Наблюдать | CVE-2020-7940Эксплойта нет | Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.plone · plone · CWE-521 | Высокая7,5 | — | 1,3 % | 23 янв. 2020 г. |
30Наблюдать | CVE-2021-33511Эксплойта нет | Plone though 5.2.4 allows SSRF via the lxml parser.plone · plone · CWE-918 | Высокая7,5 | — | 1,2 % | 21 мая 2021 г. |
- CVE-2011-358760На этой неделе
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attacke
КритическаяCVSS 9,3Готовый эксплойтEPSS 78 %plone · plone10 окт. 2011 г.
- CVE-2008-139341В плане
Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %plone · plone cms19 мар. 2008 г.
- CVE-2020-794140В плане
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needi
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %plone · plone23 янв. 2020 г.
- CVE-2020-3519040В плане
The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %plone · plone16 дек. 2020 г.
- CVE-2021-3350940В плане
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %plone · plone21 мая 2021 г.
- CVE-2024-2305439Наблюдать
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package liste
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %plone · plone docker official image5 февр. 2024 г.
- CVE-2011-403038Наблюдать
The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from bein
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %plone · cmfeditions10 окт. 2011 г.
- CVE-2015-729336Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %plone · plone25 сент. 2017 г.
- CVE-2021-3263336Наблюдать
Remote Code Execution via traversal in TAL expressions
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %zope · zope21 мая 2021 г.
- CVE-2012-548735Наблюдать
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certai
ВысокаяCVSS 8,5Эксплойта нетEPSS 2 %plone · plone30 сент. 2014 г.
- CVE-2012-549335Наблюдать
gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox
ВысокаяCVSS 8,5Эксплойта нетEPSS 2 %plone · plone30 сент. 2014 г.
- CVE-2020-793835Наблюдать
plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %plone · plone23 янв. 2020 г.
- CVE-2020-2873535Наблюдать
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %plone · plone30 дек. 2020 г.
- CVE-2020-2873635Наблюдать
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (there
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %plone · plone30 дек. 2020 г.
- CVE-2020-2873435Наблюдать
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %plone · plone30 дек. 2020 г.
- CVE-2020-793935Наблюдать
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %plone · plone23 янв. 2020 г.
- CVE-2021-3392635Наблюдать
An issue in Plone CMS v.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %plone · plone17 февр. 2023 г.
- CVE-2011-072031Наблюдать
Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain a
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %plone · plone3 февр. 2011 г.
- CVE-2007-574131Наблюдать
Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled o
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %plone · plone7 нояб. 2007 г.
- CVE-2011-252831Наблюдать
Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) Plone
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %plone · plone hotfix 2011072019 июл. 2011 г.
- CVE-2015-731831Наблюдать
Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %plone · plone25 сент. 2017 г.
- CVE-2008-139430Наблюдать
Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %plone · plone cms19 мар. 2008 г.
- CVE-2008-139530Наблюдать
Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier f
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %plone · plone cms19 мар. 2008 г.
- CVE-2020-794030Наблюдать
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %plone · plone23 янв. 2020 г.
- CVE-2021-3351130Наблюдать
Plone though 5.2.4 allows SSRF via the lxml parser.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %plone · plone21 мая 2021 г.