pypi package report

Is plone-restapi safe?

3 known vulnerabilities, worst severity HIGH.

// reach

21 direct dependencies

7 carry known advisories, worst CRITICAL

23 packages depend on it

an advisory here reaches each of them

Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage

No published models are known to use this package.


cvss
0.0
high

severity band, no base score published

epss
0.00%
medium

chance of exploitation in 30 days, 73rd percentile of all CVEs

xyz score
not scored

CyberXYZ composite out of 10

fig. 01 — GHSA-cjg3-q24h-9qwf, the advisory selected below

// 3 advisories

GHSA-cjg3-q24h-9qwf

HIGHCVE-2020-7938

plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.

// cvss v3.1 vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Checked 2026-09-26 at 06:14 UTC. The most recent advisory here was published 2026-07-17. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.