plone-app-dexterity
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting plone-app-dexteritypage 1 of 1
- CVE-2020-28734HIGHCVSS 8.8EG 8.8fixed in 2.6.82020-12-30
vulnerable: 1.0 ... 2.6.7 (95 versions)
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
- CVE-2020-28735HIGHCVSS 8.8EG 8.8fixed in 2.6.82020-12-30
vulnerable: 1.0 ... 2.6.7 (95 versions)
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
- CVE-2020-28736HIGHCVSS 8.8EG 8.8fixed in 2.6.82020-12-30
vulnerable: 1.0 ... 2.6.7 (95 versions)
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
- CVE-2026-57576MEDIUMCVSS 6.5EG 6.5fixed in 5.0.1, 4.1.3 or 3.2.3, by version range2026-09-22
vulnerable: 1.0 ... 5.0.0 (134 versions)
plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and 5.0.0, …
Check whether plone-app-dexterity is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for plone-app-dexterity CVEs against the assets you own.
Book a Demo →