Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

zopefoundation — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting zopefoundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Zope Foundation develops Zope, a Python-based content management framework and application server primarily used for building complex web applications with robust security features. Historically, its vulnerabilities have commonly included cross-site scripting (XSS), remote code execution (RCE), and privilege escalation, often stemming from input validation flaws and insecure default configurations. While Zope's security model emphasizes granular permissions and has generally avoided major high-profile incidents, the 17 recorded CVEs highlight ongoing challenges in maintaining security across its extensive feature set, particularly in third-party extensions and legacy components.

CVE ID Title CVSS Severity Published
CVE-2026-77401 Zope AccessControl: Information disclosure through Python string `format` and `format_map` functions — AccessControl CWE-693 6.8 Medium 2026-09-16
CVE-2026-76825 RestrictedPython: Sandbox escape via string.Formatter field resolution — RestrictedPython CWE-200 8.4 High 2026-09-16
CVE-2026-55830 RestrictedPython guard hooks can be shadowed via positional-only arguments — RestrictedPython CWE-184 8.3 High 2026-07-08
CVE-2025-22153 try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter — RestrictedPython CWE-843 7.9 High 2025-01-23
CVE-2024-51734 User data deletion by anoynmous users in Zope — AccessControl CWE-284 6.5AI Medium AI 2024-11-04
CVE-2024-47532 RestrictedPython information leakage via `AttributeError.obj` and the `string` module — RestrictedPython CWE-200 6.5 - 2024-09-30
CVE-2024-24811 Products.SQLAlchemyDA vulnerable to unauthenticated arbitrary SQL query execution — Products.SQLAlchemyDA CWE-89 9.8 Critical 2024-02-07
CVE-2023-44389 Zope management interface vulnerable to stored cross site scripting via the title property — Zope CWE-79 3.1 Low 2023-10-04
CVE-2023-42458 Zope vulnerable to Stored Cross Site Scripting with SVG images — Zope CWE-80 3.7 Low 2023-09-21
CVE-2023-41050 Information disclosure through Python's "format" functionality in Zope AccessControl — AccessControl CWE-200 6.8 Medium 2023-09-06
CVE-2023-41039 Sandbox escape via various forms of "format" in RestrictedPython — RestrictedPython CWE-74 8.3 High 2023-08-30
CVE-2023-37271 RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape — RestrictedPython CWE-913 8.4 High 2023-07-11
CVE-2023-36814 zopefoundation's Products.CMFCore vulnerable to unauthenticated denial of service and crash via unchecked use of input with Python's marshal module — Products.CMFCore CWE-770 7.5 High 2023-07-03
CVE-2021-32811 Remote Code Execution via Script (Python) objects under Python 3 — Zope CWE-915 7.5 High 2021-08-02
CVE-2021-32807 Remote Code Execution via unsafe classes in otherwise permitted modules — AccessControl CWE-915 4.4 Medium 2021-07-30
CVE-2021-32674 Remote Code Execution via traversal in TAL expressions — Zope CWE-22 8.8 High 2021-06-08
CVE-2021-32633 Remote Code Execution via traversal in TAL expressions — Zope CWE-22 6.8 Medium 2021-05-21
CVE-2021-21360 Exposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetup — Products.GenericSetup CWE-200 5.3 Medium 2021-03-09
CVE-2021-21337 URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService — Products.PluggableAuthService CWE-601 5.7 Medium 2021-03-08
CVE-2021-21336 Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager — Products.PluggableAuthService CWE-200 6.5 Medium 2021-03-08

This page lists every published CVE security advisory associated with zopefoundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.