-Infinity
0

pip/Products.isurlinportalProducts.isurlinportal: Possible open redirect when using more than 2 forward slashes

Risk 19
Severity
6.1
EPSS
0.04%
First published (updated )

CVE-2025-58047: DoS in Volto (Plone CMS)

pip/PloneDue to incorrect access control in Plone version v6.0.9, remote attackers can view and list all file…

Risk 45
Severity
7.5
First published (updated )

Plone ploneThe HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allo…

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )

Plone Plone Docker Official ImageAn issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remo…

Risk 61
Severity
9.8
EPSS
0.39%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Plone Plone Docker Official ImageAn issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code ex…

Risk 27
Severity
6.1
EPSS
0.13%
First published (updated )

pip/PloneCross-Frame Scripting (XFS) on Plone CMS

Risk 37
Severity
7.1
EPSS
0.05%
First published (updated )

Plone security advisory 2023/09/21

Plone restplone.rest vulnerable to Denial of Service when ++api++ is used many times

Risk 45
Severity
7.5
First published (updated )

Plone namedfileplone.namedfile vulnerable to Stored Cross Site Scripting with SVG images

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Plone ploneSSRF

Risk 82
Severity
8.8
First published (updated )

Plone Volto Node.jsImproper Authentication in Volto

Risk 70
Severity
7.5
First published (updated )

pip/Products.ATContentTypesCross-site Scripting and Open Redirect in Products.ATContentTypes

Risk 39
Severity
6.1
First published (updated )

pip/Products.isurlinportalURL Redirection to Untrusted Site ('Open Redirect') in Products.isurlinportal

Risk 39
Severity
6.5
First published (updated )

pip/ploneXSS

Risk 39
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Plone ploneXSS

Risk 39
Severity
6.1
First published (updated )

pip/PloneXSS

Risk 35
Severity
5.4
First published (updated )

pip/PlonePlone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arg…

Risk 86
Severity
10
First published (updated )

pip/PloneSSRF

Risk 23
Severity
4.3
First published (updated )

pip/PloneSSRF

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/PloneXSS

Risk 35
Severity
5.4
First published (updated )

pip/PloneXSS

Risk 35
Severity
5.4
First published (updated )

pip/ZopeRemote Code Execution via traversal in TAL expressions

Risk 82
Severity
8.8
First published (updated )

pip/ploneXSS

Risk 39
Severity
6.1
First published (updated )

pip/ploneXSS

Risk 35
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Plone ploneExposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager

Risk 40
Severity
6.5
First published (updated )

pip/plone.supermodelXEE

Risk 82
Severity
8.8
First published (updated )

pip/plone.supermodelSSRF

Risk 82
Severity
8.8
First published (updated )

pip/plone.supermodelXEE

Risk 82
Severity
8.8
First published (updated )

Plone ploneThe official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank p…

Risk 87
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203