Technology · PyPI
plone (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 101 vulnerabilities in plone (PyPI): 0 in the last 7 days and 20 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2020-7938, was published on 9 July 2026.
- Last 7 days
- 0
- Last 90 days
- 20
- Critical, all time
- 1
- Exploited in the wild
- 0
Latest plone (PyPI) vulnerabilities
- CVE-2020-7938: PYSEC-2026-2889 - Plone Privilege EscallationlowCVSS 3.1EPSS 1.5%
- CVE-2015-7315: PYSEC-2026-2964 - Plone unauthorized member addition vulnerabilitylowCVSS 3.1EPSS 2.0%
- CVE-2017-1000482: PYSEC-2026-2962 - Products.CMFPlone XSS in profile home_page propertylowCVSS 3EPSS 0.6%
- CVE-2017-1000481: PYSEC-2026-2963 - Products.CMFPlone Open Redirect VulnerabilitylowCVSS 3EPSS 0.7%
- CVE-2021-33507: PYSEC-2026-2967 - Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, PlonelowCVSS 3.1EPSS 0.8%
- CVE-2011-1950: PYSEC-2026-2888 - Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accountslowCVSS 3.1EPSS 2.4%
- CVE-2011-1948: PYSEC-2026-2966 - Cross-site scripting in Products.CMFPlone and Products.PasswordResetToollowCVSS 3.1EPSS 2.4%
- CVE-2024-22889: PYSEC-2026-1798 - Phone information disclosure vulnerabilitylowCVSS 3.1EPSS 0.7%
- CVE-2024-0669: PYSEC-2026-1797 - Cross-Frame Scripting vulnerability has been found on Plone CMSlowCVSS 3.1EPSS 0.3%
- CVE-2011-1340: PYSEC-2026-896 - Plone XSS VulnerabilityinfoEPSS 1.1%
- CVE-2011-4030: PYSEC-2026-897 - Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishableinfoEPSS 2.0%
- CVE-2008-4571: PYSEC-2026-730 - Plone Cross-site Scripting vulnerability in the LiveSearch moduleinfoEPSS 1.1%
- CVE-2008-1396: PYSEC-2026-732 - Plone credentials stored in session cookieinfoEPSS 1.1%
- CVE-2008-1393: PYSEC-2026-731 - Plone Improper Session ManagementinfoEPSS 2.9%
- CVE-2008-1394: PYSEC-2026-734 - Plone CMS Improper Session ManagementinfoEPSS 1.4%
- CVE-2006-1711: PYSEC-2026-733 - Plone allows remote users to modify arbitrary portraitsinfoEPSS 3.9%
- CVE-2020-28736: PYSEC-2026-735 - Improper Restriction of XML External Entity Reference in PlonelowCVSS 3.1EPSS 1.5%
- CVE-2020-28735: PYSEC-2026-737 - SSRF attacks via tracebacks in PlonelowCVSS 3.1EPSS 1.5%
- CVE-2020-28734: PYSEC-2026-736 - Improper Restriction of XML External Entity Reference in PlonelowCVSS 3.1EPSS 1.5%
- CVE-2020-7941: PYSEC-2026-459 - Plone Unauthenticated Write VulnerabilitylowCVSS 3.1EPSS 2.3%
- CVE-2021-33926: PYSEC-2023-289 - An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2…lowCVSS 3.1EPSS 1.0%
- CVE-2008-0164: Plone CMS CSRF in join_form and prefs_groups_overviewhighCVSS 7.5EPSS 0.7%
- CVE-2006-4249: Plone PlonePAS group masquerading via anonymous registrationmediumCVSS 5.9EPSS 1.0%
- CVE-2006-4247: Plone Password Reset Tool unauthorized password resetcriticalCVSS 9.1EPSS 1.0%
- CVE-2021-35959: PYSEC-2021-110 - In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor…lowCVSS 3.1EPSS 0.5%
Most severe plone (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2006-4247: Plone Password Reset Tool unauthorized password resetcriticalCVSS 9.1EPSS 1.0%
- CVE-2011-2528: Plone and Zope2 privilege escalation via incorrect security fixhighCVSS 7.5EPSS 2.0%
- CVE-2008-0164: Plone CMS CSRF in join_form and prefs_groups_overviewhighCVSS 7.5EPSS 0.7%
- CVE-2009-0662: Plone Products.PlonePAS improper authentication in login formmediumCVSS 6EPSS 1.0%
- CVE-2006-4249: Plone PlonePAS group masquerading via anonymous registrationmediumCVSS 5.9EPSS 1.0%
- CVE-2011-4462: PYSEC-2011-22 - Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger…lowCVSS 3.1EPSS 3.2%
- CVE-2011-0720: PYSEC-2011-13 - Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products…lowCVSS 3.1EPSS 3.2%
- CVE-2012-5498: PYSEC-2014-40 - queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and…lowCVSS 3.1EPSS 2.7%
- CVE-2012-5488: PYSEC-2014-30 - python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python…lowCVSS 3.1EPSS 2.6%
- CVE-2012-5486: PYSEC-2014-73 - ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows…lowCVSS 3.1EPSS 2.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 9 | 0 | |
| 6 Jul 2026 | 11 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pypi-plone.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "plone (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pypi-plone, 27 September 2026.