{"schema_version":1,"title":"Zope (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 20 vulnerabilities in Zope (PyPI): 0 in the last 7 days and 12 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-51734, was published on 13 July 2026.","url":"https://junglewise.ai/threats/technologies/zope","json_url":"https://junglewise.ai/threats/technologies/zope.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/zope","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":20,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":12,"last_365_days":12},"latest":[{"cve":"CVE-2024-51734","cvss":3.1,"epss":0.0043,"slug":"cve-2024-51734-access-control-vulnerable-to-user-data-deletion-by-anonynmous","title":"PYSEC-2026-2326 - Access control vulnerable to user data deletion by anonynmous users","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:32.99089+00:00","url":"https://junglewise.ai/threats/cve-2024-51734-access-control-vulnerable-to-user-data-deletion-by-anonynmous"},{"cve":"CVE-2023-41050","cvss":3.1,"epss":0.0064,"slug":"cve-2023-41050-information-disclosure-in-accesscontrol","title":"PYSEC-2026-2325 - Information disclosure in AccessControl","severity":"low","exploited":false,"published_at":"2026-07-13T14:20:02.13584+00:00","url":"https://junglewise.ai/threats/cve-2023-41050-information-disclosure-in-accesscontrol"},{"cve":"CVE-2023-42458","cvss":3.1,"epss":0.0071,"slug":"cve-2023-42458-zope-vulnerable-to-stored-cross-site-scripting-with-svg-images","title":"PYSEC-2026-2077 - Zope vulnerable to Stored Cross Site Scripting with SVG images","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:24.678692+00:00","url":"https://junglewise.ai/threats/cve-2023-42458-zope-vulnerable-to-stored-cross-site-scripting-with-svg-images"},{"cve":"CVE-2000-0483","epss":0.0297,"slug":"cve-2000-0483-zope-documenttemplate-package-allows-unauthenticated-write","title":"PYSEC-2026-760 - Zope DocumentTemplate package allows unauthenticated write","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:21.51608+00:00","url":"https://junglewise.ai/threats/cve-2000-0483-zope-documenttemplate-package-allows-unauthenticated-write"},{"cve":"CVE-2002-0687","epss":0.0148,"slug":"cve-2002-0687-zope-server-vulnerable-to-dos-via-header-injection","title":"PYSEC-2026-761 - Zope Server vulnerable to DoS via header injection","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:19.339413+00:00","url":"https://junglewise.ai/threats/cve-2002-0687-zope-server-vulnerable-to-dos-via-header-injection"},{"cve":"CVE-2002-0688","epss":0.0144,"slug":"cve-2002-0688-zcatalog-plug-in-for-zope-allows-anonymous-users-to-bypass-access","title":"PYSEC-2026-755 - ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:19.270008+00:00","url":"https://junglewise.ai/threats/cve-2002-0688-zcatalog-plug-in-for-zope-allows-anonymous-users-to-bypass-access"},{"cve":"CVE-2002-0170","epss":0.0158,"slug":"cve-2002-0170-zope-does-not-properly-verify-the-access-for-objects-with-proxy","title":"PYSEC-2026-758 - Zope does not properly verify the access for objects with proxy roles","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:19.201129+00:00","url":"https://junglewise.ai/threats/cve-2002-0170-zope-does-not-properly-verify-the-access-for-objects-with-proxy"},{"cve":"CVE-2000-1212","epss":0.0154,"slug":"cve-2000-1212-zope-allows-attackers-to-modify-raw-image-and-file-data","title":"PYSEC-2026-756 - Zope allows attackers to modify raw image and file data","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:19.133523+00:00","url":"https://junglewise.ai/threats/cve-2000-1212-zope-allows-attackers-to-modify-raw-image-and-file-data"},{"cve":"CVE-2000-1211","epss":0.0144,"slug":"cve-2000-1211-zope-does-not-properly-perform-security-registration-for-legacy","title":"PYSEC-2026-759 - Zope does not properly perform security registration for legacy names","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:19.06342+00:00","url":"https://junglewise.ai/threats/cve-2000-1211-zope-does-not-properly-perform-security-registration-for-legacy"},{"cve":"CVE-2000-0725","epss":0.0047,"slug":"cve-2000-0725-zope-does-not-properly-restrict-access-to-the-getroles-method","title":"PYSEC-2026-757 - Zope does not properly restrict access to the getRoles method","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:18.990025+00:00","url":"https://junglewise.ai/threats/cve-2000-0725-zope-does-not-properly-restrict-access-to-the-getroles-method"},{"cve":"CVE-2000-0062","epss":0.0224,"slug":"cve-2000-0062-zope-dtml-implementation-improper-authentication","title":"PYSEC-2026-762 - Zope DTML implementation Improper Authentication","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:18.910953+00:00","url":"https://junglewise.ai/threats/cve-2000-0062-zope-dtml-implementation-improper-authentication"},{"cve":"CVE-2011-4924","cvss":3.1,"epss":0.0136,"slug":"cve-2011-4924-zope-xss-vulnerability","title":"PYSEC-2026-766 - Zope XSS Vulnerability","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:17.937454+00:00","url":"https://junglewise.ai/threats/cve-2011-4924-zope-xss-vulnerability"},{"cve":"CVE-2023-44389","cvss":3.1,"epss":0.004,"slug":"cve-2023-44389-zope-management-interface-vulnerable-to-stored-cross-site","title":"PYSEC-2023-193 - Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store script code that is","severity":"low","exploited":false,"published_at":"2023-10-04T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-44389-zope-management-interface-vulnerable-to-stored-cross-site"},{"cve":"CVE-2010-3198","cvss":7.5,"epss":0.0154,"slug":"cve-2010-3198-zope-zserver-denial-of-service-via-worker-thread-crash","title":"Zope ZServer denial of service via worker thread crash","severity":"high","exploited":false,"published_at":"2022-05-17T05:48:31+00:00","url":"https://junglewise.ai/threats/cve-2010-3198-zope-zserver-denial-of-service-via-worker-thread-crash"},{"cve":"CVE-2021-32807","cvss":4.4,"epss":0.0205,"slug":"cve-2021-32807-zope-accesscontrol-remote-code-execution-via-formatter-class-in","title":"Zope AccessControl remote code execution via Formatter class in Python 3","severity":"medium","exploited":false,"published_at":"2021-08-05T17:01:30+00:00","url":"https://junglewise.ai/threats/cve-2021-32807-zope-accesscontrol-remote-code-execution-via-formatter-class-in"},{"cve":"CVE-2021-32811","cvss":3.1,"epss":0.023,"slug":"cve-2021-32811-remote-code-execution-via-script-python-objects-under-python-3","title":"PYSEC-2021-370 - Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In","severity":"low","exploited":false,"published_at":"2021-08-02T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32811-remote-code-execution-via-script-python-objects-under-python-3"},{"slug":"pysec-2021-367-the-module-accesscontrol-defines-security-policies-for-6980850d","title":"PYSEC-2021-367 - The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is an","severity":"info","exploited":false,"published_at":"2021-07-30T22:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2021-367-the-module-accesscontrol-defines-security-policies-for-6980850d"},{"cve":"CVE-2021-32674","cvss":8.8,"epss":0.0159,"slug":"cve-2021-32674-zope-rce-via-traversal-in-tal-expressions","title":"Zope RCE via traversal in TAL expressions","severity":"high","exploited":false,"published_at":"2021-06-08T18:45:52+00:00","url":"https://junglewise.ai/threats/cve-2021-32674-zope-rce-via-traversal-in-tal-expressions"},{"cve":"CVE-2021-32633","cvss":3.1,"epss":0.0186,"slug":"cve-2021-32633-remote-code-execution-via-traversal-in-tal-expressions","title":"PYSEC-2021-88 - Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules indirectly through","severity":"low","exploited":false,"published_at":"2021-05-21T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32633-remote-code-execution-via-traversal-in-tal-expressions"},{"cvss":3,"slug":"pysec-2017-148-cross-site-scripting-xss-vulnerability-in-zmi-pages-that-6369fd2d","title":"PYSEC-2017-148 - Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.","severity":"low","exploited":false,"published_at":"2017-08-07T17:29:00+00:00","url":"https://junglewise.ai/threats/pysec-2017-148-cross-site-scripting-xss-vulnerability-in-zmi-pages-that-6369fd2d"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"Zope (PyPI)","slug":"zope","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://www.zope.dev/","repo_url":"https://github.com/zopefoundation/Zope","description":"An open-source web application server written in Python.","url":"https://junglewise.ai/threats/technologies/zope"},"most_severe":[{"cve":"CVE-2021-32674","cvss":8.8,"epss":0.0159,"slug":"cve-2021-32674-zope-rce-via-traversal-in-tal-expressions","title":"Zope RCE via traversal in TAL expressions","severity":"high","exploited":false,"published_at":"2021-06-08T18:45:52+00:00","url":"https://junglewise.ai/threats/cve-2021-32674-zope-rce-via-traversal-in-tal-expressions"},{"cve":"CVE-2010-3198","cvss":7.5,"epss":0.0154,"slug":"cve-2010-3198-zope-zserver-denial-of-service-via-worker-thread-crash","title":"Zope ZServer denial of service via worker thread crash","severity":"high","exploited":false,"published_at":"2022-05-17T05:48:31+00:00","url":"https://junglewise.ai/threats/cve-2010-3198-zope-zserver-denial-of-service-via-worker-thread-crash"},{"cve":"CVE-2021-32807","cvss":4.4,"epss":0.0205,"slug":"cve-2021-32807-zope-accesscontrol-remote-code-execution-via-formatter-class-in","title":"Zope AccessControl remote code execution via Formatter class in Python 3","severity":"medium","exploited":false,"published_at":"2021-08-05T17:01:30+00:00","url":"https://junglewise.ai/threats/cve-2021-32807-zope-accesscontrol-remote-code-execution-via-formatter-class-in"},{"cve":"CVE-2021-32811","cvss":3.1,"epss":0.023,"slug":"cve-2021-32811-remote-code-execution-via-script-python-objects-under-python-3","title":"PYSEC-2021-370 - Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In","severity":"low","exploited":false,"published_at":"2021-08-02T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32811-remote-code-execution-via-script-python-objects-under-python-3"},{"cve":"CVE-2021-32633","cvss":3.1,"epss":0.0186,"slug":"cve-2021-32633-remote-code-execution-via-traversal-in-tal-expressions","title":"PYSEC-2021-88 - Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules indirectly through","severity":"low","exploited":false,"published_at":"2021-05-21T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32633-remote-code-execution-via-traversal-in-tal-expressions"},{"cve":"CVE-2011-4924","cvss":3.1,"epss":0.0136,"slug":"cve-2011-4924-zope-xss-vulnerability","title":"PYSEC-2026-766 - Zope XSS Vulnerability","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:17.937454+00:00","url":"https://junglewise.ai/threats/cve-2011-4924-zope-xss-vulnerability"},{"cve":"CVE-2023-42458","cvss":3.1,"epss":0.0071,"slug":"cve-2023-42458-zope-vulnerable-to-stored-cross-site-scripting-with-svg-images","title":"PYSEC-2026-2077 - Zope vulnerable to Stored Cross Site Scripting with SVG images","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:24.678692+00:00","url":"https://junglewise.ai/threats/cve-2023-42458-zope-vulnerable-to-stored-cross-site-scripting-with-svg-images"},{"cve":"CVE-2023-41050","cvss":3.1,"epss":0.0064,"slug":"cve-2023-41050-information-disclosure-in-accesscontrol","title":"PYSEC-2026-2325 - Information disclosure in AccessControl","severity":"low","exploited":false,"published_at":"2026-07-13T14:20:02.13584+00:00","url":"https://junglewise.ai/threats/cve-2023-41050-information-disclosure-in-accesscontrol"},{"cve":"CVE-2024-51734","cvss":3.1,"epss":0.0043,"slug":"cve-2024-51734-access-control-vulnerable-to-user-data-deletion-by-anonynmous","title":"PYSEC-2026-2326 - Access control vulnerable to user data deletion by anonynmous users","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:32.99089+00:00","url":"https://junglewise.ai/threats/cve-2024-51734-access-control-vulnerable-to-user-data-deletion-by-anonynmous"},{"cve":"CVE-2023-44389","cvss":3.1,"epss":0.004,"slug":"cve-2023-44389-zope-management-interface-vulnerable-to-stored-cross-site","title":"PYSEC-2023-193 - Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store script code that is","severity":"low","exploited":false,"published_at":"2023-10-04T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-44389-zope-management-interface-vulnerable-to-stored-cross-site"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}