Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3440
  • PyPI/zope
Zope XSS Vulnerability 09 Jul
  • Fix available
  • Severity - 6.1 (Medium)
PYSEC-2026-2076
  • PyPI/zope
Access control vulnerable to user data deletion by anonynmous users 07 Jul
  • Fix available
  • Severity - 6.6 (Medium)
PYSEC-2026-2077
  • PyPI/zope
Zope vulnerable to Stored Cross Site Scripting with SVG images 07 Jul
  • Fix available
  • Severity - 3.7 (Low)
PYSEC-2026-2075
  • PyPI/zope
Information disclosure in AccessControl 07 Jul
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-760
  • PyPI/zope
Zope DocumentTemplate package allows unauthenticated write 02 Jul
  • No fix available
PYSEC-2026-761
  • PyPI/zope
Zope Server vulnerable to DoS via header injection 02 Jul
  • Fix available
PYSEC-2026-755
  • PyPI/zope
ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions 02 Jul
  • Fix available
PYSEC-2026-758
  • PyPI/zope
Zope does not properly verify the access for objects with proxy roles 02 Jul
  • Fix available
PYSEC-2026-756
  • PyPI/zope
Zope allows attackers to modify raw image and file data 02 Jul
  • No fix available
PYSEC-2026-759
  • PyPI/zope
Zope does not properly perform security registration for legacy names 02 Jul
  • No fix available
PYSEC-2026-757
  • PyPI/zope
Zope does not properly restrict access to the getRoles method 02 Jul
  • Fix available
PYSEC-2026-762
  • PyPI/zope
Zope DTML implementation Improper Authentication 02 Jul
  • No fix available
GHSA-g5vw-3h65-2q3v
  • PyPI/accesscontrol
  • PyPI/zope
Access control vulnerable to user data deletion by anonynmous users 04 Nov 2024
  • Fix available
  • Severity - 6.6 (Medium)
PYSEC-2023-193
  • PyPI/zope
  • github.com/zopefoundation/Zope
See record for full details 04 Oct 2023
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-m755-gxxg-r5qh
  • PyPI/zope
Zope management interface vulnerable to stored cross site scripting via the title property 04 Oct 2023
  • Fix available
  • Severity - 3.1 (Low)
GHSA-wm8q-9975-xh5v
  • PyPI/zope
Zope vulnerable to Stored Cross Site Scripting with SVG images 21 Sep 2023
  • Fix available
  • Severity - 3.7 (Low)