pypi package reportIs products-cmfplone safe ? 7 known vulnerabilities, worst severity HIGH.
// reach 95 direct dependencies
15 carry known advisories, worst CRITICAL
31 packages depend on it
an advisory here reaches each of them
// ai model usage No published models are known to use this package.
cvss severity band, no base score published
epss chance of exploitation in 30 days, 80th percentile of all CVEs
xyz score CyberXYZ composite out of 10
fig. 01 — GHSA-984m-rj28-8c6x, the advisory selected below
// 7 advisories GHSA-984m-rj28-8c6x Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator. HIGH GHSA-4vr8-r7qr-fpvq Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API. MODE GHSA-rg52-j87w-pf83 Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope. MODE GHSA-859j-668v-mrr6 A member of the Plone site could set javascript in the homepage property of their profile, and have this executed when a visitor clicks the home page link on the author page. MODE GHSA-8g72-gq68-6gqh When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'camefrom' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might try to abuse this by letting you click on a specially crafted link. You would login, and get redirected to the site of the attacker, letting you think that you are MODE GHSA-8w54-22w9-3g8f Plone is vulnerable to reflected cross site scripting and open redirect when an attacker can get a compromised version of the imageviewfullscreen page in a cache, for example in Varnish. MODE GHSA-p7h9-vf92-5fj5 Cross-site scripting (XSS) vulnerability in Plone 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL. MODE Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.
// cvss v3.1 vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity High
Availability None Checked 2026-09-26 at 02:20 UTC. The most recent advisory here was published 2022-05-17. Updated continuously from NVD, GHSA, OSV and CNA feeds.
Think a verdict here is wrong? Tell us — we respond within 2 business days. Report an issue with this page