Zope is a long-established application server and object database framework that powers web applications and content-management systems, though its deployment footprint has narrowed over time. The vendor's vulnerability profile, while modest in count, spans its core runtime, object-database persistence layer (ZODB), and access-control subsystems, reflecting the architectural dependencies inherent to a full-stack application platform. The recurring weakness classes center on input-validation and output-encoding issues such as cross-site scripting, alongside information-disclosure and concurrency vulnerabilities that arise from web-request handling and shared-resource management. Vulnerabilities affecting Zope demonstrate a moderate tendency toward public exploit availability, while defenders tracking this vendor should focus on legacy deployment inventories where patches may lag significantly. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zope over time
Signals from CVEs in this vendor scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3587HIGH Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vec | Oct 10, 2011 | 9.3 | 86 | NO | YES |
CVE-2021-21337MEDIUM Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulner | Mar 8, 2021 | 6.1 | 34 | NO | YES |
CVE-2015-7293HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x. | Sep 25, 2017 | 8.8 | 32 | NO | YES |
CVE-2023-37271CRITICAL RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environment. RestrictedPython does not | Jul 11, 2023 | 9.9 | 28 | NO | NO |
CVE-2021-32674HIGH Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefoundation/Zope/security/advisories/GHSA-5pr9-v234-jw36 with ad | Jun 8, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-32633HIGH Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules indirectly through Python modules that are available for di | May 21, 2021 | 8.8 | 27 | NO | NO |
CVE-2009-0669HIGH Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass authentication via vectors invol | Aug 7, 2009 | 7.5 | 25 | NO | NO |
CVE-2000-0062HIGH The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities. | Jan 4, 2000 | 10.0 | 25 | NO | NO |
CVE-2024-24811CRITICAL SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on the data | Feb 7, 2024 | 9.8 | 24 | NO | NO |
CVE-2021-32807HIGH The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is any code that resides in Zope's object dat | Jul 30, 2021 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (51 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zope.
Media articles that mention a CVE ID that affects a product developed by Zope — matched by CVE ID, not by vendor name.