Vulnerabilidades en plone
11 resultadosAnálisis Vexday
O Plone apresenta um perfil de risco baixo com apenas 7 CVEs registradas e nenhuma sob ataque ativo atualmente. A fraqueza dominante é redirecionamento aberto (CWE-601), típica de aplicações web, sem críticas de CVSS identificadas e nenhuma vulnerabilidade publicada nos últimos 90 dias, indicando um histórico estável.
CVE-2021-32806MEDIUMURL Redirection to Untrusted Site ('Open Redirect') in Products.isurlinportalEPSS 1.0%CVE-2023-42457HIGHplone.rest vulnerable to Denial of Service when ++api++ is used many timesEPSS 0.8%CVE-2025-58047HIGHVolto affected by possible DoS by invoking specific URL by anonymous userEPSS 0.6%CVE-2022-24740MEDIUMImproper Authentication in VoltoEPSS 0.6%CVE-2023-41048LOWplone.namedfile vulnerable to Stored Cross Site Scripting with SVG imagesEPSS 0.5%CVE-2025-61668HIGH@plone/volto vulnerable to potential DoS by invoking specific URL by anonymous userEPSS 0.4%CVE-2026-55247CRITICALplone.app.event: Denial of service via iCalendar importEPSS 0.3%CVE-2026-55248CRITICALplone.app.portlets: Denial of service via RSS feed portletEPSS 0.3%CVE-2026-54503MEDIUMplone.app.textfield: Stored XSS by spoofing mime typeEPSS 0.2%CVE-2026-28413MEDIUMProducts.isurlinportal: Possible open redirect when using more than 2 forward slashesEPSS 0.2%CVE-2026-57149CRITICALplone.app.portlets Vulnerable to Remote Code Execution via TALES InjectionEPSS —