Junglewise Threat Intelligence

CVE-2020-28734: PYSEC-2026-736 - Improper Restriction of XML External Entity Reference in Plone

CVE-2020-28734 · Severity: low · CVSS 3.1 · Published 2026-07-02

Technologies: plone-app-theming (PyPI), plone-supermodel (PyPI), plone (PyPI), plone.app.dexterity (PyPI), plone.app.event (PyPI). Vendors: PyPI.

Executive brief

Improper Restriction of XML External Entity Reference in Plone

Affected products

  • PyPI plone-app-theming
  • PyPI plone-supermodel
  • PyPI plone
  • PyPI plone.app.dexterity
  • PyPI plone.app.event

Related threats