Dependency scanning
Check whether plone is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-0669
Cross-Frame Scripting vulnerability has been found on Plone CMS
CVE-2020-7941
Plone Unauthenticated Write Vulnerability
CVE-2020-7938
CVE-2020-7938
CVE-2020-7938
Plone Privilege Escallation
CVE-2020-28736
CVE-2020-28736
CVE-2020-28736
Improper Restriction of XML External Entity Reference in Plone
CVE-2020-28735
CVE-2020-28735
CVE-2020-28735
SSRF attacks via tracebacks in Plone
CVE-2020-28734
CVE-2020-28734
CVE-2020-28734
Improper Restriction of XML External Entity Reference in Plone
CVE-2011-1950
CVE-2011-1950
CVE-2011-1950
Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts
CVE-2021-33507
CVE-2021-33507
CVE-2021-33507
Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone
CVE-2011-1948
CVE-2011-1948
CVE-2011-1948
Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool
CVE-2015-7315
CVE-2015-7315
CVE-2015-7315
Plone unauthorized member addition vulnerability
CVE-2017-1000481
CVE-2017-1000481
CVE-2017-1000481
Products.CMFPlone Open Redirect Vulnerability
CVE-2017-1000482
CVE-2017-1000482
CVE-2017-1000482
Products.CMFPlone XSS in profile home_page property
CVE-2006-4247
CVE-2006-4247
CVE-2006-4247
Plone allows anonymous users to reset any users password through the web via Password Reset Tool
CVE-2006-4249
CVE-2006-4249
CVE-2006-4249
Plone allows a user to masquerade as a group
CVE-2008-0164
CVE-2008-0164
CVE-2008-0164
Plone Cross-site request forgery (CSRF)
CVE-2011-2528
CVE-2011-2528
CVE-2011-2528
High severity vulnerability that affects Plone and Zope2
CVE-2011-2528
CVE-2011-2528
CVE-2008-0164
CVE-2008-0164
CVE-2006-4247
CVE-2006-4247
CVE-2006-4249
CVE-2006-4249
CVE-2024-22889
Phone information disclosure vulnerability
CVE-2024-0669
Cross-Frame Scripting vulnerability has been found on Plone CMS
CVE-2024-22889
Phone information disclosure vulnerability
CVE-2011-4030
Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
CVE-2011-1340
Plone XSS Vulnerability
CVE-2011-1340
Plone XSS Vulnerability
CVE-2011-4030
Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
CVE-2008-1393
Plone Improper Session Management
CVE-2008-1394
Plone CMS Improper Session Management
CVE-2006-1711
Plone allows remote users to modify arbitrary portraits
CVE-2009-0662
CVE-2009-0662
CVE-2008-1396
Plone credentials stored in session cookie
CVE-2008-4571
Plone Cross-site Scripting vulnerability in the LiveSearch module
CVE-2008-1396
Plone credentials stored in session cookie
CVE-2008-1393
Plone Improper Session Management
CVE-2008-4571
Plone Cross-site Scripting vulnerability in the LiveSearch module
CVE-2008-1394
Plone CMS Improper Session Management
CVE-2006-1711
Plone allows remote users to modify arbitrary portraits
CVE-2007-5741
CVE-2007-5741
CVE-2020-7941
CVE-2020-7941
CVE-2015-7316
CVE-2015-7316
CVE-2021-35959
CVE-2021-35959
CVE-2012-5496
CVE-2012-5496
CVE-2012-5497
CVE-2012-5497
CVE-2012-5495
CVE-2012-5495
CVE-2012-5494
CVE-2012-5494
CVE-2012-5492
CVE-2012-5492
CVE-2012-5493
CVE-2012-5493
CVE-2012-5491
CVE-2012-5491
CVE-2012-5488
CVE-2012-5488
CVE-2012-5487
CVE-2012-5487
CVE-2012-5485
CVE-2012-5485
CVE-2010-2422
CVE-2010-2422
CVE-2011-0720
CVE-2011-0720
CVE-2021-3313
CVE-2021-3313
CVE-2020-7940
CVE-2020-7940
CVE-2020-7939
CVE-2020-7939
CVE-2013-7062
CVE-2013-7062
CVE-2017-1000483
CVE-2017-1000483
CVE-2020-7937
CVE-2020-7937
CVE-2020-7936
CVE-2020-7936
CVE-2016-7139
CVE-2016-7139
CVE-2016-7140
CVE-2016-7140
CVE-2016-7147
CVE-2016-7147
CVE-2016-7138
CVE-2016-7138
CVE-2016-7137
CVE-2016-7137
CVE-2016-7135
CVE-2016-7135
CVE-2016-4043
CVE-2016-4043
CVE-2013-4194
CVE-2013-4194
CVE-2013-4193
CVE-2013-4193
CVE-2013-4195
CVE-2013-4195
CVE-2015-7293
CVE-2015-7293
CVE-2013-4192
CVE-2013-4192
CVE-2013-4191
CVE-2013-4191
CVE-2016-4041
CVE-2016-4041
CVE-2016-4042
CVE-2016-4042
CVE-2013-4190
CVE-2013-4190
CVE-2015-7318
CVE-2015-7318
CVE-2016-7136
CVE-2016-7136
CVE-2013-4200
CVE-2013-4200
CVE-2012-5490
CVE-2012-5490
CVE-2013-4199
CVE-2013-4199
CVE-2013-4198
CVE-2013-4198
CVE-2013-4197
CVE-2013-4197
CVE-2013-4196
CVE-2013-4196
CVE-2013-4188
CVE-2013-4188
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes