Known Vulnerabilities for Plone by Plone
Listed below are 10 of the newest known vulnerabilities associated with "Plone" by "Plone".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2024-0669 json | 7.1 - HIGH | 2024-01-18 | 2024-01-26 | |
| CVE-2023-41048 json | plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity content. Pr... | 5.4 - MEDIUM | 2023-09-21 | 2023-09-26 |
| CVE-2022-23599 json | Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products.ATCo... | 6.1 - MEDIUM | 2022-01-28 | 2023-06-27 |
| CVE-2021-35959 json | In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder ... | 5.4 - MEDIUM | 2021-06-30 | 2021-07-02 |
| CVE-2021-33926 json | An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, ... | 8.8 - HIGH | 2023-02-17 | 2023-03-02 |
| CVE-2021-33513 json | Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool. | 5.4 - MEDIUM | 2021-05-21 | 2021-05-24 |
| CVE-2021-33512 json | Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document. | 5.4 - MEDIUM | 2021-05-21 | 2021-05-24 |
| CVE-2021-33511 json | Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plo... | 7.5 - HIGH | 2021-05-21 | 2021-05-24 |
| CVE-2021-33510 json | Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a... | 4.3 - MEDIUM | 2021-05-21 | 2021-05-24 |
| CVE-2021-33509 json | Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructure... | 9.9 - CRITICAL | 2021-05-21 | 2021-05-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Plone | Plone | 5.2.3 | |||
| Application | Plone | Plone | 5.2.2 | |||
| Application | Plone | Plone | 5.2.1 | |||
| Application | Plone | Plone | 5.2.0 | |||
| Application | Plone | Plone | 5.2 | |||
| Application | Plone | Plone | 5.2 | |||
| Application | Plone | Plone | 5.2 | |||
| Application | Plone | Plone | 5.2 | |||
| Application | Plone | Plone | 5.2 | |||
| Application | Plone | Plone | 5.1a1 | |||
| Application | Plone | Plone | 5.1.7 | |||
| Application | Plone | Plone | 5.1.6 | |||
| Application | Plone | Plone | 5.1.5 | |||
| Application | Plone | Plone | 5.1.4 | |||
| Application | Plone | Plone | 5.1.3 | |||
| Application | Plone | Plone | 5.1.2 | |||
| Application | Plone | Plone | 5.1.1 | |||
| Application | Plone | Plone | 5.1 | |||
| Application | Plone | Plone | 5.1 | |||
| Application | Plone | Plone | 5.1 |