products-cmfplone
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting products-cmfplonepage 1 of 1
- CVE-2011-1948MEDIUMCVSS v2 4.3EG 4.3fixed in 4.0.7 or 4.1rc3, by version range2011-06-06
vulnerable: 4.0b1 ... 4.1rc2 (7 versions)
Cross-site scripting (XSS) vulnerability in Plone 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
- CVE-2013-7060MEDIUMCVSS v2 5.0EG 5.0fixed in 4.3.32014-05-02
vulnerable: 4.0b1 ... 4.3rc1 (39 versions)
Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope.
- CVE-2013-7061MEDIUMCVSS v2 5.5EG 5.5fixed in 4.3.32014-05-02
vulnerable: 4.0b1 ... 4.3rc1 (39 versions)
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
- CVE-2015-7315MEDIUMCVSS 5.9EG 5.9fixed in 4.3.7 or 5.0rc2, by version range2017-09-25
vulnerable: 4.0b1 ... 5.0rc1 (53 versions)
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of sit…
- CVE-2017-1000481MEDIUMCVSS 6.1EG 6.1fixed in 4.3.17, 5.0.10 or 5.1.0, by version range2018-01-03
vulnerable: 4.0b1 ... 5.1rc2 (80 versions)
When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might t…
- CVE-2017-1000482MEDIUMCVSS 5.4EG 5.4fixed in 4.3.17, 5.0.10 or 5.1.0, by version range2018-01-03
vulnerable: 4.0b1 ... 5.1rc2 (80 versions)
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
Check whether products-cmfplone is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for products-cmfplone CVEs against the assets you own.
Book a Demo →