-Infinity
0

pip/RestrictedPythonRestrictedPython information leakage via `AttributeError.obj` and the `string` module

Risk 49
Severity
8.7
First published (updated )

Zope Application Server(0Day) Zope CMFCore Uncontrolled Resource Consumption Denial-of-Service Vulnerability

Risk 23
First published (updated )
Advisory
ZDI-24-841

Zope Zope Application ServerZDI-24-841: (0Day) Zope CMFCore Uncontrolled Resource Consumption Denial-of-Service Vulnerability

Risk 23
First published (updated )

pip/Products.SQLAlchemyDAProducts.SQLAlchemyDA vulnerable to unauthenticated arbitrary SQL query execution

Risk 62
Severity
9.8
EPSS
0.13%
First published (updated )

pip/ZopeZope management interface vulnerable to stored cross site scripting via the title property

Risk 30
Severity
4.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/ZopeZope vulnerable to Stored Cross Site Scripting with SVG images

Risk 34
Severity
5.4
First published (updated )

pip/AccessControlInformation disclosure through Python's "format" functionality in Zope AccessControl

Risk 44
Severity
7.7
First published (updated )

pip/RestrictedPythonSandbox escape via various forms of "format" in RestrictedPython

Risk 63
Severity
8.3
First published (updated )

Zope RestrictedPythonRestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape

Risk 84
Severity
9.9
First published (updated )

pip/Products.CMFCorezopefoundation's Products.CMFCore vulnerable to unauthenticated denial of service and crash via unchecked use of input with Python's marshal module

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/ZopeRemote Code Execution via Script (Python) objects under Python 3

Risk 73
Severity
7.5
First published (updated )

pip/AccessControlRemote Code Execution via unsafe classes in otherwise permitted modules

Risk 69
Severity
7.2
First published (updated )

Zope GrokBuffer Overflow

Risk 68
Severity
7.8
First published (updated )

pip/ZopeRemote Code Execution via traversal in TAL expressions

Risk 82
Severity
8.8
First published (updated )

Plone ploneXSS

Risk 39
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/ZopeRemote Code Execution via traversal in TAL expressions

Risk 82
Severity
8.8
First published (updated )

Zope Products.GenericSetupExposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetup

Risk 28
Severity
5.3
First published (updated )

pip/Products.PluggableAuthServiceURL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService

Risk 39
Severity
6.1
First published (updated )

Plone ploneExposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager

Risk 40
Severity
6.5
First published (updated )

Zope ZopeXSS

Risk 39
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Plone ploneCSRF

Risk 80
Severity
8.8
First published (updated )

Zope ZopeXSS

Risk 39
Severity
6.1
First published (updated )

Plone ploneZope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo…

Risk 45
Severity
7.5
First published (updated )

Plone ploneThe App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2…

Risk 40
Severity
6.5
First published (updated )

Plone ploneRace Condition

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Plone ploneXSS

Risk 46
Severity
7.5
First published (updated )

Zope ZopeUnspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and …

Risk 83
Severity
9.3
First published (updated )

Zope ZopePlone upstream has published a pre-announcement about a security flaw, present in Zope v2.12.x and Z…

Risk 19
Severity
4
First published (updated )

Plone ploneUnspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plo…

Risk 55
Severity
7.5
First published (updated )

Plone ploneIt was reported [1] that Plone suffers from a vulnerability that can be exploited to bypass certain …

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203