plone
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting plone.
- CVE-2026-57576plone.app.dexterity and plone.app.contenttypes have a Denial of Service due to excessive title or description length6.5
- CVE-2026-57149plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection9.9
- CVE-2026-54503plone.app.textfield: Stored XSS by spoofing mime type4.3
- CVE-2026-55247plone.app.event: Denial of service via iCalendar import9.1
- CVE-2026-55248plone.app.portlets: Denial of service via RSS feed portlet9.1
- CVE-2026-28413Products.isurlinportal: Possible open redirect when using more than 2 forward slashes5.3
- CVE-2025-61668@plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user
- CVE-2025-58047Volto affected by possible DoS by invoking specific URL by anonymous user7.5
- CVE-2024-22889Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.7.5
- CVE-2024-23756The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server...7.5
- CVE-2024-23054An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the publi...9.8
- CVE-2024-23055An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.6.1
- CVE-2024-0669Cross-Frame Scripting (XFS) on Plone CMS6.3
- CVE-2023-42457plone.rest vulnerable to Denial of Service when ++api++ is used many times7.5
- CVE-2023-41048plone.namedfile vulnerable to Stored Cross Site Scripting with SVG images3.7