Dependency scanning
Check whether zope is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2023-42458
Zope vulnerable to Stored Cross Site Scripting with SVG images
CVE-2023-44389
Zope management interface vulnerable to stored cross site scripting via the title property
CVE-2023-41050
Information disclosure in AccessControl
CVE-2023-41050
Information disclosure in AccessControl
CVE-2011-4924
Zope XSS Vulnerability
CVE-2011-4924
Zope XSS Vulnerability
CVE-2024-51734
Access control vulnerable to user data deletion by anonynmous users
CVE-2024-51734
Access control vulnerable to user data deletion by anonynmous users
CVE-2010-3198
CVE-2010-3198
CVE-2021-32674
CVE-2021-32674
CVE-2021-32674
Remote Code Execution via traversal in TAL expressions
CVE-2021-32674
Duplicate Advisory: Path Traversal in Zope
CVE-2021-32811
CVE-2021-32811
CVE-2021-32811
Remote Code Execution via Script (Python) objects under Python 3
CVE-2021-32633
CVE-2021-32633
CVE-2021-32633
Duplicate Advisory: Path Traversal in Zope
CVE-2021-32633
Remote Code Execution via traversal in TAL expressions
CVE-2010-3198
CVE-2010-3198
CVE-2010-3198
Zope Denial of Service (DoS) vulnerability in ZServer
CVE-2021-32807
CVE-2021-32807
CVE-2021-32807
Remote Code Execution via unsafe classes in otherwise permitted modules
CVE-2023-42458
Zope vulnerable to Stored Cross Site Scripting with SVG images
CVE-2000-1212
Zope allows attackers to modify raw image and file data
CVE-2002-0688
ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions
CVE-2000-1211
Zope does not properly perform security registration for legacy names
CVE-2000-0483
Zope DocumentTemplate package allows unauthenticated write
CVE-2000-0725
Zope does not properly restrict access to the getRoles method
CVE-2000-0062
Zope DTML implementation Improper Authentication
CVE-2002-0170
Zope does not properly verify the access for objects with proxy roles
CVE-2002-0687
Zope Server vulnerable to DoS via header injection
CVE-2002-0687
Zope Server vulnerable to DoS via header injection
CVE-2000-1211
Zope does not properly perform security registration for legacy names
CVE-2000-0062
Zope DTML implementation Improper Authentication
CVE-2000-0483
Zope DocumentTemplate package allows unauthenticated write
CVE-2002-0170
Zope does not properly verify the access for objects with proxy roles
CVE-2000-0725
Zope does not properly restrict access to the getRoles method
CVE-2000-1212
Zope allows attackers to modify raw image and file data
CVE-2002-0688
ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions
PYSEC-2017-148
PYSEC-2017-148
CVE-2023-44389
CVE-2023-44389
PYSEC-2021-367
PYSEC-2021-367
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes