41 Total advisories
41 Vulnerabilities
0 Malware

Dependency scanning

Check whether zope is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

LOW 3.7
PyPI

CVE-2023-42458

Zope vulnerable to Stored Cross Site Scripting with SVG images

LOW 3.1
PyPI

CVE-2023-44389

Zope management interface vulnerable to stored cross site scripting via the title property

MEDIUM 6.8
PyPI

CVE-2023-41050

Information disclosure in AccessControl

MEDIUM 6.8
PyPI

CVE-2023-41050

Information disclosure in AccessControl

MEDIUM 6.1
PyPI

CVE-2011-4924

Zope XSS Vulnerability

MEDIUM 6.1
PyPI

CVE-2011-4924

Zope XSS Vulnerability

CRITICAL 9.1
PyPI

CVE-2024-51734

Access control vulnerable to user data deletion by anonynmous users

CRITICAL 9.1
PyPI

CVE-2024-51734

Access control vulnerable to user data deletion by anonynmous users

UNKNOWN
PyPI

CVE-2010-3198

CVE-2010-3198

UNKNOWN
PyPI

CVE-2021-32674

CVE-2021-32674

HIGH 8.8
PyPI

CVE-2021-32674

Remote Code Execution via traversal in TAL expressions

HIGH 8.8
PyPI

CVE-2021-32674

Duplicate Advisory: Path Traversal in Zope

UNKNOWN
PyPI

CVE-2021-32811

CVE-2021-32811

HIGH 7.5
PyPI

CVE-2021-32811

Remote Code Execution via Script (Python) objects under Python 3

UNKNOWN
PyPI

CVE-2021-32633

CVE-2021-32633

HIGH 8.8
PyPI

CVE-2021-32633

Duplicate Advisory: Path Traversal in Zope

MEDIUM 6.8
PyPI

CVE-2021-32633

Remote Code Execution via traversal in TAL expressions

UNKNOWN
PyPI

CVE-2010-3198

CVE-2010-3198

HIGH 7.5
PyPI

CVE-2010-3198

Zope Denial of Service (DoS) vulnerability in ZServer

UNKNOWN
PyPI

CVE-2021-32807

CVE-2021-32807

MEDIUM 4.4
PyPI

CVE-2021-32807

Remote Code Execution via unsafe classes in otherwise permitted modules

LOW 3.7
PyPI

CVE-2023-42458

Zope vulnerable to Stored Cross Site Scripting with SVG images

UNKNOWN
PyPI

CVE-2000-1212

Zope allows attackers to modify raw image and file data

UNKNOWN
PyPI

CVE-2002-0688

ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions

UNKNOWN
PyPI

CVE-2000-1211

Zope does not properly perform security registration for legacy names

UNKNOWN
PyPI

CVE-2000-0483

Zope DocumentTemplate package allows unauthenticated write

UNKNOWN
PyPI

CVE-2000-0725

Zope does not properly restrict access to the getRoles method

UNKNOWN
PyPI

CVE-2000-0062

Zope DTML implementation Improper Authentication

UNKNOWN
PyPI

CVE-2002-0170

Zope does not properly verify the access for objects with proxy roles

UNKNOWN
PyPI

CVE-2002-0687

Zope Server vulnerable to DoS via header injection

UNKNOWN
PyPI

CVE-2002-0687

Zope Server vulnerable to DoS via header injection

UNKNOWN
PyPI

CVE-2000-1211

Zope does not properly perform security registration for legacy names

UNKNOWN
PyPI

CVE-2000-0062

Zope DTML implementation Improper Authentication

UNKNOWN
PyPI

CVE-2000-0483

Zope DocumentTemplate package allows unauthenticated write

UNKNOWN
PyPI

CVE-2002-0170

Zope does not properly verify the access for objects with proxy roles

UNKNOWN
PyPI

CVE-2000-0725

Zope does not properly restrict access to the getRoles method

UNKNOWN
PyPI

CVE-2000-1212

Zope allows attackers to modify raw image and file data

UNKNOWN
PyPI

CVE-2002-0688

ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions

MEDIUM 6.1
PyPI

PYSEC-2017-148

PYSEC-2017-148

MEDIUM 4.8
PyPI

CVE-2023-44389

CVE-2023-44389

UNKNOWN
PyPI

PYSEC-2021-367

PYSEC-2021-367

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes