Vulnerabilities > Plone > High

DATE CVE VULNERABILITY TITLE RISK
2020-01-23 CVE-2020-7940 Weak Password Requirements vulnerability in Plone
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
network
low complexity
plone CWE-521
7.5
2020-01-23 CVE-2020-7939 SQL Injection vulnerability in Plone
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries.
network
low complexity
plone CWE-89
8.8
2020-01-23 CVE-2020-7938 Unspecified vulnerability in Plone 5.2.0/5.2.1
plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.
network
low complexity
plone
8.8
2017-09-25 CVE-2015-7293 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
network
low complexity
plone zope CWE-352
8.8
2017-09-25 CVE-2015-7318 Improper Input Validation vulnerability in Plone
Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.
network
low complexity
plone CWE-20
7.5
2017-02-24 CVE-2016-4041 Permissions, Privileges, and Access Controls vulnerability in Plone
Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors.
network
low complexity
plone CWE-264
7.3