Skip to main contentSkip to navigationSkip to footer
Plone.org logo

Why Plone

  • What is Plone?
  • Features
  • Plone 6
  • They use Plone
  • Extend Plone
  • Roadmap
  • Plone as a Headless CMS
  • Frequently asked questions

Why Plone

Get Started with Plone

  • Try Plone
  • Install Plone
  • Documentation
  • Training

Get Started

Services

  • Providers
  • Training

Services

Community

  • Bugs
  • Conferences
  • Contribute
  • Forum
  • Google Summer of Code
  • Online Chat
  • Support
  • Teams

Community

Plone Foundation

  • About
  • Membership
  • Sponsor Plone
  • Board of Directors
  • Financial statements
  • Board and Member Meetings
  • Plone Event and Sprint Sponsorship Policy
  • Copyright, Licensing: Plone Code & Logo
  • Contact us

Foundation

News and Events

  • News
  • Events
  • Podcasts
  • Plone Podcast
  • The Plone Newsroom
  • Plone Labs
  • Plone Hands-On
  • Plone in Social Media
  • Plone YouTube channel
  • Plone Tune-Up Days
  • Sprints

Highlights

  • Plone Conference 2026
  • World Plone Day 2026
  • Join the Plone Newsletter
News and Events
Try now
Home

Search results

13 results
Sort by:

20111004

AKA 20113587 or 20110928
Read More…

20110628

AKA 20112528 or 20110622
Read More…

20110208

AKK 20110720
Read More…

20110601

AKA 20110531
Read More…

Privilege escalation

Anonymous users can create users with arbitrary roles
Read More…

Reflected XSS

Read More…

Persistent XSS

This is a persistent cross-site scripting (XSS) attack. It allows a user to craft markup that bypasses Plone's safe_html filter to insert and save arbitrary HTML with malicious content.
Read More…

Privilege escalation

This is an escalation of privileges attack which makes it possible for an authenticated Plone user to edit the properties of other users, bypassing authorization checks.
Read More…

Privilege escalation

A highly serious vulnerability in Zope that allows unauthorised access
Read More…

Arbitrary code execution

A vulnerability in Zope 2.12.x and Zope 2.13.x that allows execution of arbitrary code by anonymous users.
Read More…

20121106

AKA 20121106
Read More…

Restricted Python injection

Anonymous users can cause an arbitrary Python statement to be run when the admin interface is accessed. No breakout of the in-built Python sandbox is possible, but it will run with the privileges of that admin user.
Read More…

Reflexive HTTP header injection

A crafted URL can contain arbitrary HTTP headers that are then returned to the user. Can be used to log users out, for example.
Read More…
About Plone
Try Plone
Download Plone
Plone Releases
Documentation
Training
Security
Roadmap
GitHub
Community
Forum
Chat
Contribute code
Report an issue
News and events
Conference
Join the Plone newsletter
Foundation
Join the foundation
Board
Donate
Sponsors
Apply for Event and Sprint Funds
Code of conduct
Foundation members
Shop
Follow us
Mastodon
Twitter
Instagram
YouTube
Linkedin
Facebook
Privacy Policy
Cookie settings
Plone.org logo
The text and illustrations in this website are licensed by the Plone Foundation under a Creative Commons Attribution-ShareAlike 4.0 International license. Plone and the Plone® logo are registered trademarks of the Plone Foundation, registered in the United States and other countries. For guidelines on the permitted uses of the Plone trademarks, see https://plone.org/foundation/logo. All other trademarks are owned by their respective owners.