Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Zope

53 known vulnerabilities

1
CRITICAL
7
HIGH
10
MEDIUM
2
LOW

Top Products

zope 9 restrictedpython 3 accesscontrol 3 products.pluggableauthservice 2 sqlalchemyda 1 products.cmfcore 1 grok 1 products.genericsetup 1 zope management interface 1
20 CVEs
6.5
CVE-2024-47532

RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to prote

9.8
CVE-2024-24811

SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unaut

3.1
CVE-2023-44389

Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store

3.7
CVE-2023-42458

Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scriptin

6.8
CVE-2023-41050

AccessControl provides a general security framework for use in Zope. Python's "format" functionality allows someone cont

8.3
CVE-2023-41039

RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality

8.4
CVE-2023-37271

RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program

7.5
CVE-2023-36814

Products.CMFCore are the key framework services for the Zope Content Management Framework (CMF). The use of Python's mar

7.5
CVE-2021-32811

Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code executio

4.4
CVE-2021-32807

The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. R

7.8
CVE-2021-36089

Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from g

8.8
CVE-2021-32674

Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefou

6.1
CVE-2021-33507

Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and ot

6.8
CVE-2021-32633

Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules

5.3
CVE-2021-21360

Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem arti

5.7
CVE-2021-21337

Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS

6.5
CVE-2021-21336

Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS

6.1
CVE-2011-4924

Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x

8.8
CVE-2015-7293

Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone bef

6.1
CVE-2009-5145

Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2

Frequently Asked Questions

How many CVEs affect Zope?

Zope has 53 CVE records in our database, including 1 critical and 21 high severity vulnerabilities.

What are the most severe Zope vulnerabilities?

Zope has 1 critical severity (CVSS 9.0+) and 21 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Zope vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Zope products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Zope Vulnerabilities

CyberStrike scans your infrastructure for Zope vulnerabilities and provides real-time remediation guidance.

Get Started