plone kayıtları
plone üreticisine ait 116 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %0,9
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %92,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')28
- CWE-264 Permissions, Privileges, and Access Controls15
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor9
- CWE-20 Improper Input Validation6
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')6
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
116 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2011-3587Silahlaştırılmış | Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackeplone · plone | Kritik9,3 | — | %78,1 | 10 Eki 2011 |
41Planlayın | CVE-2008-1393İstismar yok | Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the adminplone · plone cms · CWE-255 | Kritik10,0 | — | %2,9 | 19 Mar 2008 |
40Planlayın | CVE-2020-7941İstismar yok | A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without neediplone · plone | Kritik9,8 | — | %2,3 | 23 Oca 2020 |
40Planlayın | CVE-2020-35190İstismar yok | The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user.plone · plone · CWE-306 | Kritik9,8 | — | %2,2 | 16 Ara 2020 |
40Planlayın | CVE-2021-33509İstismar yok | Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transformplone · plone · CWE-732 | Kritik9,9 | — | %2,0 | 21 May 2021 |
39İzleyin | CVE-2024-23054İstismar yok | An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listeplone · plone docker official image · CWE-427 | Kritik9,8 | — | %1,3 | 5 Şub 2024 |
38İzleyin | CVE-2011-4030İstismar yok | The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from beinplone · cmfeditions · CWE-264 | Kritik9,3 | — | %2,0 | 10 Eki 2011 |
36İzleyin | CVE-2015-7293Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.plone · plone · CWE-352 | Yüksek8,8 | — | %3,0 | 25 Eyl 2017 |
36İzleyin | CVE-2021-32633İstismar yok | Remote Code Execution via traversal in TAL expressionszope · zope · CWE-22 | Yüksek8,8 | — | %1,9 | 21 May 2021 |
35İzleyin | CVE-2012-5487İstismar yok | The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certaiplone · plone · CWE-264 | Yüksek8,5 | — | %1,7 | 30 Eyl 2014 |
35İzleyin | CVE-2012-5493İstismar yok | gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox plone · plone · CWE-94 | Yüksek8,5 | — | %1,7 | 30 Eyl 2014 |
35İzleyin | CVE-2020-7938İstismar yok | plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.plone · plone | Yüksek8,8 | — | %1,5 | 23 Oca 2020 |
35İzleyin | CVE-2020-28735İstismar yok | Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).plone · plone · CWE-918 | Yüksek8,8 | — | %1,5 | 30 Ara 2020 |
35İzleyin | CVE-2020-28736İstismar yok | Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (thereplone · plone · CWE-611 | Yüksek8,8 | — | %1,5 | 30 Ara 2020 |
35İzleyin | CVE-2020-28734İstismar yok | Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.plone · plone · CWE-611 | Yüksek8,8 | — | %1,5 | 30 Ara 2020 |
35İzleyin | CVE-2020-7939İstismar yok | SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries.plone · plone · CWE-89 | Yüksek8,8 | — | %1,2 | 23 Oca 2020 |
35İzleyin | CVE-2021-33926İstismar yok | An issue in Plone CMS v.plone · plone · CWE-918 | Yüksek8,8 | — | %1,0 | 17 Şub 2023 |
31İzleyin | CVE-2011-0720İstismar yok | Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain aplone · plone | Yüksek7,5 | — | %3,2 | 3 Şub 2011 |
31İzleyin | CVE-2007-5741İstismar yok | Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled oplone · plone · CWE-94 | Yüksek7,5 | — | %2,2 | 7 Kas 2007 |
31İzleyin | CVE-2011-2528İstismar yok | Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) Ploneplone · plone hotfix 20110720 | Yüksek7,5 | — | %2,0 | 19 Tem 2011 |
31İzleyin | CVE-2015-7318İstismar yok | Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.plone · plone · CWE-20 | Yüksek7,5 | — | %1,7 | 25 Eyl 2017 |
30İzleyin | CVE-2008-1394İstismar yok | Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easierplone · plone cms · CWE-255 | Yüksek7,5 | — | %1,4 | 19 Mar 2008 |
30İzleyin | CVE-2008-1395İstismar yok | Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier fplone · plone cms · CWE-287 | Yüksek7,5 | — | %1,3 | 19 Mar 2008 |
30İzleyin | CVE-2020-7940İstismar yok | Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.plone · plone · CWE-521 | Yüksek7,5 | — | %1,3 | 23 Oca 2020 |
30İzleyin | CVE-2021-33511İstismar yok | Plone though 5.2.4 allows SSRF via the lxml parser.plone · plone · CWE-918 | Yüksek7,5 | — | %1,2 | 21 May 2021 |
- CVE-2011-358760Bu hafta
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attacke
KritikCVSS 9,3SilahlaştırılmışEPSS %78plone · plone10 Eki 2011
- CVE-2008-139341Planlayın
Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin
KritikCVSS 10,0İstismar yokEPSS %3plone · plone cms19 Mar 2008
- CVE-2020-794140Planlayın
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needi
KritikCVSS 9,8İstismar yokEPSS %2plone · plone23 Oca 2020
- CVE-2020-3519040Planlayın
The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user.
KritikCVSS 9,8İstismar yokEPSS %2plone · plone16 Ara 2020
- CVE-2021-3350940Planlayın
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform
KritikCVSS 9,9İstismar yokEPSS %2plone · plone21 May 2021
- CVE-2024-2305439İzleyin
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package liste
KritikCVSS 9,8İstismar yokEPSS %1plone · plone docker official image5 Şub 2024
- CVE-2011-403038İzleyin
The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from bein
KritikCVSS 9,3İstismar yokEPSS %2plone · cmfeditions10 Eki 2011
- CVE-2015-729336İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
YüksekCVSS 8,8Kavram kanıtıEPSS %3plone · plone25 Eyl 2017
- CVE-2021-3263336İzleyin
Remote Code Execution via traversal in TAL expressions
YüksekCVSS 8,8İstismar yokEPSS %2zope · zope21 May 2021
- CVE-2012-548735İzleyin
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certai
YüksekCVSS 8,5İstismar yokEPSS %2plone · plone30 Eyl 2014
- CVE-2012-549335İzleyin
gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox
YüksekCVSS 8,5İstismar yokEPSS %2plone · plone30 Eyl 2014
- CVE-2020-793835İzleyin
plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.
YüksekCVSS 8,8İstismar yokEPSS %1plone · plone23 Oca 2020
- CVE-2020-2873535İzleyin
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
YüksekCVSS 8,8İstismar yokEPSS %1plone · plone30 Ara 2020
- CVE-2020-2873635İzleyin
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (there
YüksekCVSS 8,8İstismar yokEPSS %1plone · plone30 Ara 2020
- CVE-2020-2873435İzleyin
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
YüksekCVSS 8,8İstismar yokEPSS %1plone · plone30 Ara 2020
- CVE-2020-793935İzleyin
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries.
YüksekCVSS 8,8İstismar yokEPSS %1plone · plone23 Oca 2020
- CVE-2021-3392635İzleyin
An issue in Plone CMS v.
YüksekCVSS 8,8İstismar yokEPSS %1plone · plone17 Şub 2023
- CVE-2011-072031İzleyin
Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain a
YüksekCVSS 7,5İstismar yokEPSS %3plone · plone3 Şub 2011
- CVE-2007-574131İzleyin
Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled o
YüksekCVSS 7,5İstismar yokEPSS %2plone · plone7 Kas 2007
- CVE-2011-252831İzleyin
Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) Plone
YüksekCVSS 7,5İstismar yokEPSS %2plone · plone hotfix 2011072019 Tem 2011
- CVE-2015-731831İzleyin
Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.
YüksekCVSS 7,5İstismar yokEPSS %2plone · plone25 Eyl 2017
- CVE-2008-139430İzleyin
Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier
YüksekCVSS 7,5İstismar yokEPSS %1plone · plone cms19 Mar 2008
- CVE-2008-139530İzleyin
Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier f
YüksekCVSS 7,5İstismar yokEPSS %1plone · plone cms19 Mar 2008
- CVE-2020-794030İzleyin
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
YüksekCVSS 7,5İstismar yokEPSS %1plone · plone23 Oca 2020
- CVE-2021-3351130İzleyin
Plone though 5.2.4 allows SSRF via the lxml parser.
YüksekCVSS 7,5İstismar yokEPSS %1plone · plone21 May 2021