Vulnerabilities > Plone > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-01-25 CVE-2024-23055 Unspecified vulnerability in Plone Docker Official Image 5.2.13
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.
network
low complexity
plone
6.1
2023-09-21 CVE-2023-41048 Cross-site Scripting vulnerability in Plone Namedfile 6.2.0
plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity content.
network
low complexity
plone CWE-79
5.4
2022-01-28 CVE-2022-23599 Open Redirect vulnerability in Plone
Products.ATContentTypes are the core content types for Plone 2.1 - 4.3.
network
low complexity
plone CWE-601
6.1
2021-08-02 CVE-2021-32806 Unspecified vulnerability in Plone Isurlinportal 1.0.0/1.1.0/1.1.1
Products.isurlinportal is a replacement for isURLInPortal method in Plone.
network
low complexity
plone
6.1
2021-06-30 CVE-2021-35959 Cross-site Scripting vulnerability in Plone
In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.
network
low complexity
plone CWE-79
5.4
2021-05-21 CVE-2021-33507 Cross-site Scripting vulnerability in multiple products
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.
network
low complexity
plone zope CWE-79
6.1
2021-05-21 CVE-2021-33508 Cross-site Scripting vulnerability in Plone
Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item.
network
low complexity
plone CWE-79
5.4
2021-05-21 CVE-2021-33510 Server-Side Request Forgery (SSRF) vulnerability in Plone
Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file.
network
low complexity
plone CWE-918
4.3
2021-05-21 CVE-2021-33512 Cross-site Scripting vulnerability in Plone
Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document.
network
low complexity
plone CWE-79
5.4
2021-05-21 CVE-2021-33513 Cross-site Scripting vulnerability in Plone
Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool.
network
low complexity
plone CWE-79
5.4