📦 Plone

by Plone

🔍 What is Plone?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-33509

CRITICAL CVSS 9.9 May 21, 2021

This vulnerability allows remote authenticated managers in Plone to perform arbitrary disk I/O operations via crafted keyword arguments to the ReStructuredText transform in Python scripts. Attackers c...

CVE-2020-35190

CRITICAL CVSS 9.8 Dec 17, 2020

This vulnerability allows remote attackers to gain root access to systems running affected Plone Docker images by using a blank password for the root user. It affects deployments using official Plone ...

CVE-2024-22889

HIGH CVSS 7.5 Mar 6, 2024

CVE-2024-22889 is an access control vulnerability in Plone v6.0.9 that allows remote attackers to view and list all files hosted on the website via crafted requests. This affects all Plone v6.0.9 inst...

CVE-2024-23756

HIGH CVSS 7.5 Feb 8, 2024

This vulnerability allows unauthenticated attackers to use HTTP PUT and DELETE methods in Plone Docker version 5.2.13, enabling them to upload malicious files or delete existing files on the server. I...

CVE-2021-33511

HIGH CVSS 7.5 May 21, 2021

CVE-2021-33511 is a Server-Side Request Forgery (SSRF) vulnerability in Plone CMS that allows attackers to make unauthorized requests from the server to internal or external systems. It affects Plone ...