Vulnerabilities > Plone > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-23 | CVE-2020-7940 | Weak Password Requirements vulnerability in Plone Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking. | 7.5 |
2020-01-23 | CVE-2020-7939 | SQL Injection vulnerability in Plone SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. | 8.8 |
2020-01-23 | CVE-2020-7938 | Unspecified vulnerability in Plone 5.2.0/5.2.1 plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level. | 8.8 |
2017-09-25 | CVE-2015-7293 | Cross-Site Request Forgery (CSRF) vulnerability in multiple products Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x. | 8.8 |
2017-09-25 | CVE-2015-7318 | Improper Input Validation vulnerability in Plone Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses. | 7.5 |
2017-02-24 | CVE-2016-4041 | Permissions, Privileges, and Access Controls vulnerability in Plone Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors. | 7.3 |