pypi package report

Is plone-supermodel safe?

3 known vulnerabilities, worst severity HIGH.

// reach

10 direct dependencies

1 carry known advisories, worst HIGH

31 packages depend on it

an advisory here reaches each of them

Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage

No published models are known to use this package.


cvss
0.0
high

severity band, no base score published

epss
0.00%
medium

chance of exploitation in 30 days, 72nd percentile of all CVEs

xyz score
not scored

CyberXYZ composite out of 10

fig. 01 — GHSA-wq6x-g685-w5f2, the advisory selected below

// 3 advisories

GHSA-wq6x-g685-w5f2

HIGHCVE-2020-28734

Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.

// cvss v3.1 vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Checked 2026-09-26 at 04:33 UTC. The most recent advisory here was published 2021-04-07. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.