Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-4137
  • PyPI/plone-app-dexterity
plone.app.dexterity has a Denial of Service due to excessive title or description length 01 Oct
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-4138
  • PyPI/plone-app-portlets
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection 01 Oct
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-8pcw-h6w9-h46g
  • PyPI/plone-app-contenttypes
plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length 23 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-5426-92w4-wvhv
  • PyPI/plone-app-dexterity
plone.app.dexterity has a Denial of Service due to excessive title or description length 23 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-rr49-f9g6-c9r5
  • PyPI/plone-app-portlets
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection 23 Sep
  • Fix available
  • Severity - 9.9 (Critical)
PYSEC-2026-3883
  • PyPI/plone-app-event
plone.app.event vulnerable to denial of service via iCalendar import 10 Sep
  • Fix available
  • Severity - 9.1 (Critical)
PYSEC-2026-3884
  • PyPI/plone-app-portlets
plone.app.portlets vulnerable to denial of service via RSS feed portlet 10 Sep
  • Fix available
  • Severity - 9.1 (Critical)
MAL-2026-15577
  • PyPI/auth-app-streamlit
Malicious code in auth-app-streamlit (PyPI) 30 Aug
  • No fix available
GHSA-r82h-mqw3-fc56
  • PyPI/plone-app-event
plone.app.event vulnerable to denial of service via iCalendar import 28 Aug
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-x5g3-w747-2h8q
  • PyPI/plone-app-portlets
plone.app.portlets vulnerable to denial of service via RSS feed portlet 28 Aug
  • Fix available
  • Severity - 9.1 (Critical)
PYSEC-2026-3497
  • PyPI/plone-app-textfield
plone.app.textfield: Stored XSS by spoofing mime type 23 Jul
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-4r4f-gg25-rmg5
  • PyPI/plone-app-textfield
plone.app.textfield: Stored XSS by spoofing mime type 17 Jul
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-8f6j-263m-g72x
  • PyPI/app-store-server-library
Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks 13 Jul
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-2879
  • PyPI/plone-app-dexterity
Improper Restriction of XML External Entity Reference in Plone 09 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-2885
  • PyPI/plone-app-theming
Improper Restriction of XML External Entity Reference in Plone 09 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-2882
  • PyPI/plone-app-event
Improper Restriction of XML External Entity Reference in Plone 09 Jul
  • Fix available
  • Severity - 8.7 (High)