Zope
This hub aggregates every CVE we track for Zope, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
38
CVEs tracked
2
Critical
12
High
0
In CISA KEV
Severity distribution
MEDIUM18HIGH12LOW5CRITICAL2
Monthly trend
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Zope.
- CVE-2024-51734User data deletion by anoynmous users in Zope
- CVE-2023-44389Zope management interface vulnerable to stored cross site scripting via the title property3.1
- CVE-2023-42458Zope vulnerable to Stored Cross Site Scripting with SVG images3.7
- CVE-2023-41050Information disclosure through Python's "format" functionality in Zope AccessControl6.8
- CVE-2021-32811Remote Code Execution via Script (Python) objects under Python 37.5
- CVE-2021-32807Remote Code Execution via unsafe classes in otherwise permitted modules4.4
- CVE-2021-32674Remote Code Execution via traversal in TAL expressions8.8
- CVE-2021-33507Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.6.1
- CVE-2021-32633Remote Code Execution via traversal in TAL expressions6.8
- CVE-2011-4924Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote ...6.1
- CVE-2009-5145Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4, 2.10.2, 2.10.1, 2.12.6.1
- CVE-2012-6661Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value vi...5.0
- CVE-2012-5507AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in ...4.3
- CVE-2012-5486ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.6.4
- CVE-2012-5489The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to...6.5
Product normalization is registry-driven with AI assist and human review. How it works