{"schema_version":1,"title":"plone (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 101 vulnerabilities in plone (PyPI): 0 in the last 7 days and 20 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2020-7938, was published on 9 July 2026.","url":"https://junglewise.ai/threats/technologies/pypi-plone","json_url":"https://junglewise.ai/threats/technologies/pypi-plone.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-plone","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":101,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":20,"last_365_days":20},"latest":[{"cve":"CVE-2020-7938","cvss":3.1,"epss":0.0147,"slug":"cve-2020-7938-plone-privilege-escallation","title":"PYSEC-2026-2889 - Plone Privilege Escallation","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:47.293067+00:00","url":"https://junglewise.ai/threats/cve-2020-7938-plone-privilege-escallation"},{"cve":"CVE-2015-7315","cvss":3.1,"epss":0.0202,"slug":"cve-2015-7315-plone-unauthorized-member-addition-vulnerability","title":"PYSEC-2026-2964 - Plone unauthorized member addition vulnerability","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:46.423703+00:00","url":"https://junglewise.ai/threats/cve-2015-7315-plone-unauthorized-member-addition-vulnerability"},{"cve":"CVE-2017-1000482","cvss":3,"epss":0.0057,"slug":"cve-2017-1000482-products-cmfplone-xss-in-profile-home-page-property","title":"PYSEC-2026-2962 - Products.CMFPlone XSS in profile home_page property","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:46.136141+00:00","url":"https://junglewise.ai/threats/cve-2017-1000482-products-cmfplone-xss-in-profile-home-page-property"},{"cve":"CVE-2017-1000481","cvss":3,"epss":0.0069,"slug":"cve-2017-1000481-products-cmfplone-open-redirect-vulnerability","title":"PYSEC-2026-2963 - Products.CMFPlone Open Redirect Vulnerability","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:46.07496+00:00","url":"https://junglewise.ai/threats/cve-2017-1000481-products-cmfplone-open-redirect-vulnerability"},{"cve":"CVE-2021-33507","cvss":3.1,"epss":0.0075,"slug":"cve-2021-33507-plone-reflected-cross-site-scripting-vulnerability","title":"PYSEC-2026-2967 - Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:33.633106+00:00","url":"https://junglewise.ai/threats/cve-2021-33507-plone-reflected-cross-site-scripting-vulnerability"},{"cve":"CVE-2011-1950","cvss":3.1,"epss":0.0235,"slug":"cve-2011-1950-plone-privilege-escalation-in-account-property-modification","title":"PYSEC-2026-2888 - Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:32.377883+00:00","url":"https://junglewise.ai/threats/cve-2011-1950-plone-privilege-escalation-in-account-property-modification"},{"cve":"CVE-2011-1948","cvss":3.1,"epss":0.0239,"slug":"cve-2011-1948-cross-site-scripting-in-products-cmfplone-and-products","title":"PYSEC-2026-2966 - Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:32.099972+00:00","url":"https://junglewise.ai/threats/cve-2011-1948-cross-site-scripting-in-products-cmfplone-and-products"},{"cve":"CVE-2024-22889","cvss":3.1,"epss":0.007,"slug":"cve-2024-22889-phone-information-disclosure-vulnerability","title":"PYSEC-2026-1798 - Phone information disclosure vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:34.190735+00:00","url":"https://junglewise.ai/threats/cve-2024-22889-phone-information-disclosure-vulnerability"},{"cve":"CVE-2024-0669","cvss":3.1,"epss":0.0029,"slug":"cve-2024-0669-cross-frame-scripting-vulnerability-has-been-found-on-plone-cms","title":"PYSEC-2026-1797 - Cross-Frame Scripting vulnerability has been found on Plone CMS","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:30.650365+00:00","url":"https://junglewise.ai/threats/cve-2024-0669-cross-frame-scripting-vulnerability-has-been-found-on-plone-cms"},{"cve":"CVE-2011-1340","epss":0.0115,"slug":"cve-2011-1340-plone-xss-vulnerability","title":"PYSEC-2026-896 - Plone XSS Vulnerability","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:27.502739+00:00","url":"https://junglewise.ai/threats/cve-2011-1340-plone-xss-vulnerability"},{"cve":"CVE-2011-4030","epss":0.0199,"slug":"cve-2011-4030-plone-anonymous-access-to-sub-objects-in-cmfeditions-where","title":"PYSEC-2026-897 - Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:27.332968+00:00","url":"https://junglewise.ai/threats/cve-2011-4030-plone-anonymous-access-to-sub-objects-in-cmfeditions-where"},{"cve":"CVE-2008-4571","epss":0.0115,"slug":"cve-2008-4571-plone-cross-site-scripting-vulnerability-in-the-livesearch-module","title":"PYSEC-2026-730 - Plone Cross-site Scripting vulnerability in the LiveSearch module","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:21.174937+00:00","url":"https://junglewise.ai/threats/cve-2008-4571-plone-cross-site-scripting-vulnerability-in-the-livesearch-module"},{"cve":"CVE-2008-1396","epss":0.0114,"slug":"cve-2008-1396-plone-credentials-stored-in-session-cookie","title":"PYSEC-2026-732 - Plone credentials stored in session cookie","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:20.99643+00:00","url":"https://junglewise.ai/threats/cve-2008-1396-plone-credentials-stored-in-session-cookie"},{"cve":"CVE-2008-1393","epss":0.029,"slug":"cve-2008-1393-plone-improper-session-management","title":"PYSEC-2026-731 - Plone Improper Session Management","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:20.921783+00:00","url":"https://junglewise.ai/threats/cve-2008-1393-plone-improper-session-management"},{"cve":"CVE-2008-1394","epss":0.0144,"slug":"cve-2008-1394-plone-cms-improper-session-management","title":"PYSEC-2026-734 - Plone CMS Improper Session Management","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:20.849677+00:00","url":"https://junglewise.ai/threats/cve-2008-1394-plone-cms-improper-session-management"},{"cve":"CVE-2006-1711","epss":0.0392,"slug":"cve-2006-1711-plone-allows-remote-users-to-modify-arbitrary-portraits","title":"PYSEC-2026-733 - Plone allows remote users to modify arbitrary portraits","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:19.823848+00:00","url":"https://junglewise.ai/threats/cve-2006-1711-plone-allows-remote-users-to-modify-arbitrary-portraits"},{"cve":"CVE-2020-28736","cvss":3.1,"epss":0.0145,"slug":"cve-2020-28736-plone-xml-external-entity-injection-in-schema-editor","title":"PYSEC-2026-735 - Improper Restriction of XML External Entity Reference in Plone","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:10.056554+00:00","url":"https://junglewise.ai/threats/cve-2020-28736-plone-xml-external-entity-injection-in-schema-editor"},{"cve":"CVE-2020-28735","cvss":3.1,"epss":0.0145,"slug":"cve-2020-28735-ssrf-attacks-via-tracebacks-in-plone","title":"PYSEC-2026-737 - SSRF attacks via tracebacks in Plone","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:09.993688+00:00","url":"https://junglewise.ai/threats/cve-2020-28735-ssrf-attacks-via-tracebacks-in-plone"},{"cve":"CVE-2020-28734","cvss":3.1,"epss":0.0145,"slug":"cve-2020-28734-improper-restriction-of-xml-external-entity-reference-in-plone","title":"PYSEC-2026-736 - Improper Restriction of XML External Entity Reference in Plone","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:09.907843+00:00","url":"https://junglewise.ai/threats/cve-2020-28734-improper-restriction-of-xml-external-entity-reference-in-plone"},{"cve":"CVE-2020-7941","cvss":3.1,"epss":0.0227,"slug":"cve-2020-7941-plone-unauthenticated-write-vulnerability","title":"PYSEC-2026-459 - Plone Unauthenticated Write Vulnerability","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:32.119427+00:00","url":"https://junglewise.ai/threats/cve-2020-7941-plone-unauthenticated-write-vulnerability"},{"cve":"CVE-2021-33926","cvss":3.1,"epss":0.0101,"slug":"cve-2021-33926-server-side-request-forgery-in-plone-cms","title":"PYSEC-2023-289 - An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5","severity":"low","exploited":false,"published_at":"2023-02-17T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-33926-server-side-request-forgery-in-plone-cms"},{"cve":"CVE-2008-0164","cvss":7.5,"epss":0.0065,"slug":"cve-2008-0164-plone-cms-csrf-in-join-form-and-prefs-groups-overview","title":"Plone CMS CSRF in join_form and prefs_groups_overview","severity":"high","exploited":false,"published_at":"2022-05-01T23:28:05+00:00","url":"https://junglewise.ai/threats/cve-2008-0164-plone-cms-csrf-in-join-form-and-prefs-groups-overview"},{"cve":"CVE-2006-4249","cvss":5.9,"epss":0.0101,"slug":"cve-2006-4249-plone-plonepas-group-masquerading-via-anonymous-registration","title":"Plone PlonePAS group masquerading via anonymous registration","severity":"medium","exploited":false,"published_at":"2022-05-01T07:16:48+00:00","url":"https://junglewise.ai/threats/cve-2006-4249-plone-plonepas-group-masquerading-via-anonymous-registration"},{"cve":"CVE-2006-4247","cvss":9.1,"epss":0.0101,"slug":"cve-2006-4247-plone-password-reset-tool-unauthorized-password-reset","title":"Plone Password Reset Tool unauthorized password reset","severity":"critical","exploited":false,"published_at":"2022-05-01T07:16:48+00:00","url":"https://junglewise.ai/threats/cve-2006-4247-plone-password-reset-tool-unauthorized-password-reset"},{"cve":"CVE-2021-35959","cvss":3.1,"epss":0.0054,"slug":"cve-2021-35959-plone-has-stored-xss-in-folder-contents","title":"PYSEC-2021-110 - In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT t","severity":"low","exploited":false,"published_at":"2021-06-30T01:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-35959-plone-has-stored-xss-in-folder-contents"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":11},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":78,"url":"https://junglewise.ai/threats/technologies/picklescan"}],"technology":{"hub":true,"name":"plone (PyPI)","slug":"pypi-plone","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/pypi-plone"},"most_severe":[{"cve":"CVE-2006-4247","cvss":9.1,"epss":0.0101,"slug":"cve-2006-4247-plone-password-reset-tool-unauthorized-password-reset","title":"Plone Password Reset Tool unauthorized password reset","severity":"critical","exploited":false,"published_at":"2022-05-01T07:16:48+00:00","url":"https://junglewise.ai/threats/cve-2006-4247-plone-password-reset-tool-unauthorized-password-reset"},{"cve":"CVE-2011-2528","cvss":7.5,"epss":0.0203,"slug":"cve-2011-2528-plone-and-zope2-privilege-escalation-via-incorrect-security-fix","title":"Plone and Zope2 privilege escalation via incorrect security fix","severity":"high","exploited":false,"published_at":"2018-07-23T19:52:02+00:00","url":"https://junglewise.ai/threats/cve-2011-2528-plone-and-zope2-privilege-escalation-via-incorrect-security-fix"},{"cve":"CVE-2008-0164","cvss":7.5,"epss":0.0065,"slug":"cve-2008-0164-plone-cms-csrf-in-join-form-and-prefs-groups-overview","title":"Plone CMS CSRF in join_form and prefs_groups_overview","severity":"high","exploited":false,"published_at":"2022-05-01T23:28:05+00:00","url":"https://junglewise.ai/threats/cve-2008-0164-plone-cms-csrf-in-join-form-and-prefs-groups-overview"},{"cve":"CVE-2009-0662","cvss":6,"epss":0.0097,"slug":"cve-2009-0662-plone-products-plonepas-improper-authentication-in-login-form","title":"Plone Products.PlonePAS improper authentication in login form","severity":"medium","exploited":false,"published_at":"2018-07-23T19:50:29+00:00","url":"https://junglewise.ai/threats/cve-2009-0662-plone-products-plonepas-improper-authentication-in-login-form"},{"cve":"CVE-2006-4249","cvss":5.9,"epss":0.0101,"slug":"cve-2006-4249-plone-plonepas-group-masquerading-via-anonymous-registration","title":"Plone PlonePAS group masquerading via anonymous registration","severity":"medium","exploited":false,"published_at":"2022-05-01T07:16:48+00:00","url":"https://junglewise.ai/threats/cve-2006-4249-plone-plonepas-group-masquerading-via-anonymous-registration"},{"cve":"CVE-2011-4462","cvss":3.1,"epss":0.0322,"slug":"cve-2011-4462-plone-denial-of-service-vulnerability","title":"PYSEC-2011-22 - Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, whi","severity":"low","exploited":false,"published_at":"2011-12-30T01:55:00+00:00","url":"https://junglewise.ai/threats/cve-2011-4462-plone-denial-of-service-vulnerability"},{"cve":"CVE-2011-0720","cvss":3.1,"epss":0.032,"slug":"cve-2011-0720-plone-privilege-escalation-vulnerability","title":"PYSEC-2011-13 - Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain a","severity":"low","exploited":false,"published_at":"2011-02-03T17:00:00+00:00","url":"https://junglewise.ai/threats/cve-2011-0720-plone-privilege-escalation-vulnerability"},{"cve":"CVE-2012-5498","cvss":3.1,"epss":0.0267,"slug":"cve-2012-5498-plone-denial-of-service-via-caching-bypass","title":"PYSEC-2014-40 - queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a cr","severity":"low","exploited":false,"published_at":"2014-09-30T14:55:00+00:00","url":"https://junglewise.ai/threats/cve-2012-5498-plone-denial-of-service-via-caching-bypass"},{"cve":"CVE-2012-5488","cvss":3.1,"epss":0.0261,"slug":"cve-2012-5488-plone-code-injection-vulnerability","title":"PYSEC-2014-30 - python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to c","severity":"low","exploited":false,"published_at":"2014-09-30T14:55:00+00:00","url":"https://junglewise.ai/threats/cve-2012-5488-plone-code-injection-vulnerability"},{"cve":"CVE-2012-5486","cvss":3.1,"epss":0.0252,"slug":"cve-2012-5486-http-header-injection-in-plone-and-zope2","title":"PYSEC-2014-73 - ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrar","severity":"low","exploited":false,"published_at":"2014-09-30T14:55:00+00:00","url":"https://junglewise.ai/threats/cve-2012-5486-http-header-injection-in-plone-and-zope2"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}