Zope
53 known vulnerabilities
Top Products
RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to prote
SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unaut
Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store
Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scriptin
AccessControl provides a general security framework for use in Zope. Python's "format" functionality allows someone cont
RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality
RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program
Products.CMFCore are the key framework services for the Zope Content Management Framework (CMF). The use of Python's mar
Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code executio
The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. R
Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from g
Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefou
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and ot
Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules
Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem arti
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone bef
Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2
Frequently Asked Questions
How many CVEs affect Zope?
Zope has 53 CVE records in our database, including 1 critical and 21 high severity vulnerabilities.
What are the most severe Zope vulnerabilities?
Zope has 1 critical severity (CVSS 9.0+) and 21 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Zope vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Zope products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Zope Vulnerabilities
CyberStrike scans your infrastructure for Zope vulnerabilities and provides real-time remediation guidance.
Get Started