Plone is a content-management system and framework for building web applications, with vulnerabilities concentrated in its core platform and related components such as CMFEditions and official container images. The exposure recurs through application-layer weakness classes including cross-site scripting, sensitive information disclosure, open redirects, and improper input validation—characteristic of web-facing systems that handle user-submitted content and authentication. Despite the vendor's presence across a moderately represented vulnerability footprint, the disclosed flaws reflect the input-handling and data-exposure risks inherent to web platforms rather than memory-safety or systemic privilege-escalation patterns. Defenders should treat Plone deployments as standard web-application instances, prioritizing patching for any exposure to user-controlled input or internet-reachable endpoints. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plone over time
Signals from CVEs in this vendor scope (116 CVEs).
116 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3587HIGH Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vec | Oct 10, 2011 | 9.3 | 86 | NO | YES |
CVE-2015-7293HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x. | Sep 25, 2017 | 8.8 | 32 | NO | YES |
CVE-2024-23055MEDIUM An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers. | Jan 25, 2024 | 6.1 | 31 | NO | YES |
CVE-2021-33509CRITICAL Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script. | May 21, 2021 | 9.9 | 30 | NO | NO |
CVE-2020-7941CRITICAL A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission. | Jan 23, 2020 | 9.8 | 30 | NO | NO |
CVE-2024-23054CRITICAL An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not exis | Feb 5, 2024 | 9.8 | 29 | NO | NO |
CVE-2020-28735HIGH Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role). | Dec 30, 2020 | 8.8 | 28 | NO | NO |
CVE-2011-0720HIGH Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arb | Feb 3, 2011 | 7.5 | 28 | NO | NO |
CVE-2021-33926HIGH An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, | Feb 17, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-32633HIGH Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules indirectly through Python modules that are available for di | May 21, 2021 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (116 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plone.
Media articles that mention a CVE ID that affects a product developed by Plone — matched by CVE ID, not by vendor name.