Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.
"https://github.com/pypa/advisory-database/blob/main/vulns/plone/PYSEC-2021-79.yaml"