pypi package report

Is products-cmfplone safe?

7 known vulnerabilities, worst severity HIGH.

// reach

95 direct dependencies

15 carry known advisories, worst CRITICAL

31 packages depend on it

an advisory here reaches each of them

Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage

No published models are known to use this package.


cvss
0.0
high

severity band, no base score published

epss
0.00%
medium

chance of exploitation in 30 days, 80th percentile of all CVEs

xyz score
not scored

CyberXYZ composite out of 10

fig. 01 — GHSA-984m-rj28-8c6x, the advisory selected below

// 7 advisories

GHSA-984m-rj28-8c6x

HIGHCVE-2015-7315

Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.

// cvss v3.1 vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Checked 2026-09-26 at 02:20 UTC. The most recent advisory here was published 2022-05-17. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.