products-cmfplone
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting products-cmfplonepage 1 of 1
- CVE-2011-1948NONECVSS 0.0EG 0.0✓ Fixed in 4.1rc32011-06-06
vulnerable: 4.1a1 ... 4.1rc2 (6 versions)
Cross-site scripting (XSS) vulnerability in Plone 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
- CVE-2013-7060NONECVSS 0.0EG 0.0✓ Fixed in 4.3.32014-05-02
vulnerable: 4.0b1 ... 4.3rc1 (39 versions)
Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope.
- CVE-2013-7061NONECVSS 0.0EG 0.0✓ Fixed in 4.3.32014-05-02
vulnerable: 4.0b1 ... 4.3rc1 (39 versions)
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
- CVE-2015-7315MEDIUMCVSS 5.9EG 5.9✓ Fixed in 5.0rc22017-09-25
vulnerable: 5.0a1 ... 5.0rc1 (9 versions)
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of sit…
- CVE-2017-1000481MEDIUMCVSS 6.1EG 6.1✓ Fixed in 5.1.02018-01-03
vulnerable: 5.1a1 ... 5.1rc2 (7 versions)
When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might t…
- CVE-2017-1000482MEDIUMCVSS 5.4EG 5.4✓ Fixed in 5.1.02018-01-03
vulnerable: 5.1a1 ... 5.1rc2 (7 versions)
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
Check whether products-cmfplone is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for products-cmfplone CVEs against the assets you own.
Start Free Scan →