pypi package report

Is plone-app-event safe?

4 known vulnerabilities, worst severity CRITICAL.

// reach

38 direct dependencies

10 carry known advisories, worst CRITICAL

4 packages depend on it

an advisory here reaches each of them

Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage

No published models are known to use this package.


cvss
0.0
critical

severity out of 10

epss
0.00%
medium

chance of exploitation in 30 days, 36th percentile of all CVEs

xyz score
not scored

CyberXYZ composite out of 10

fig. 01 — GHSA-r82h-mqw3-fc56, the advisory selected below

// 4 advisories

GHSA-r82h-mqw3-fc56

CRITICALCVE-2026-55247
// impact

By abusing the iCalendar import functionality, a logged-in editor could take the whole site offline, make the server reach into the internal network and read calendar files off disk (SSRF), and store XSS.

// patches

The problem has been patched in plone.app.event.

  • For Plone 6.2: upgrade to plone.app.event 6.0.1
  • For Plone 6.1: upgrade to plone.app.event 5.2.4
  • For Plone 6.0: upgrade to plone.app.event 5.2.4
// workarounds

In the site root, go to the Security tab of the Zope Management Interface (manageaccess), look for the "plone.app.event: Import Ical" permission, and grant this only to the Manager role. Then only users with the Manager role can use the ical import form.

There is no workaround for the stored XSS in the URL field of events.

The vulnerabilities were discovered by Timothy Dudley and responsibly reported to the [Plone Security Team](mailto:security@plone.org). Thank you!

// cvss v3.1 vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
High

Checked 2026-09-26 at 04:38 UTC. The most recent advisory here was published 2026-08-28. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.