Vulnerabilities > Plone > Plone > 3.3

DATE CVE VULNERABILITY TITLE RISK
2011-07-19 CVE-2011-2528 Remote Security vulnerability in Zope
Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix20110720 for Plone 3.x allows attackers to gain privileges via unspecified vectors, related to a "highly serious vulnerability." NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-0720.
network
low complexity
plone zope
7.5
2011-06-06 CVE-2011-1949 Cross-Site Scripting vulnerability in Plone
Cross-site scripting (XSS) vulnerability in the safe_html filter in Products.PortalTransforms in Plone 2.1 through 4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-2422.
network
plone CWE-79
3.5
2011-02-03 CVE-2011-0720 Remote Security Bypass vulnerability in Plone
Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.
network
low complexity
plone redhat
7.5
2010-06-24 CVE-2010-2422 Cross-Site Scripting vulnerability in Plone
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transform.
network
plone CWE-79
4.3