Vulnerabilities > Zope > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-30 CVE-2024-47532 Unspecified vulnerability in Zope Restrictedpython
RestrictedPython is a restricted execution environment for Python to run untrusted code.
network
low complexity
zope
6.5
2023-10-04 CVE-2023-44389 Unspecified vulnerability in Zope
Zope is an open-source web application server.
network
low complexity
zope
4.8
2023-09-21 CVE-2023-42458 Unspecified vulnerability in Zope
Zope is an open-source web application server.
network
low complexity
zope
5.4
2021-05-21 CVE-2021-33507 Cross-site Scripting vulnerability in multiple products
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.
network
low complexity
plone zope CWE-79
6.1
2021-03-09 CVE-2021-21360 Unspecified vulnerability in Zope Products.Genericsetup
Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts.
network
low complexity
zope
5.3
2021-03-08 CVE-2021-21337 Unspecified vulnerability in Zope Products.Pluggableauthservice
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework.
network
low complexity
zope
6.1
2021-03-08 CVE-2021-21336 Products.PluggableAuthService is a pluggable Zope authentication and authorization framework.
network
low complexity
zope plone
6.5
2019-11-25 CVE-2011-4924 Cross-site Scripting vulnerability in Zope
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1.
network
low complexity
zope CWE-79
6.1
2017-08-07 CVE-2009-5145 Cross-site Scripting vulnerability in Zope
Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4, 2.10.2, 2.10.1, 2.12.
network
low complexity
zope CWE-79
6.1