Plone Cms
Vendor:
First CVE: Mar 20, 2008 · Active for 18 years
5
Total CVEs
More Total CVEs than 77% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Plone Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 2008
18 years ago
Most Recent CVE
Mar 20, 2008
6,701 days ago
CVE Severity & Scoring
Plone Cms5 CVEs
40%
60%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown5 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown5 (100.0%)
User Interaction
None0 (0.0%)
Unknown5 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (100.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1393HIGH Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for remo | Mar 20, 2008 | 10.0 | 27 | NO | NO |
CVE-2008-1394HIGH Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access b | Mar 20, 2008 | 7.5 | 21 | NO | NO |
CVE-2008-1395HIGH Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for context-dependent attackers to reuse | Mar 20, 2008 | 7.5 | 21 | NO | NO |
CVE-2008-0164MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote attackers to (1) add arbitrary accounts via the join_form page and (2) change t | Mar 20, 2008 | 4.3 | 16 | NO | NO |
CVE-2008-1396MEDIUM Plone CMS 3.x uses invariant data (a client username and a server secret) when calculating an HMAC-SHA1 value for an authentication cookie, which makes it easier for remote attacke | Mar 20, 2008 | 4.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Plone Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.6 | 1 | 4.3 | 0.6% | 0 | 0 |
| 3.0.5 | 1 | 4.3 | 0.6% | 0 | 0 |
| 2.5 | 1 | 7.5 | 1.4% | 0 | 0 |
| 2.1.3 | 1 | 7.5 | 1.4% | 0 | 0 |
| 2.1.2 | 1 | 7.5 | 1.4% | 0 | 0 |
| 2.0.5 | 1 | 7.5 | 1.4% | 0 | 0 |