CVE-2015-7315: Plone
Medium severity, CVSS 5.9. EPSS: 2% chance of exploitation in the next 30 days.
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.
Affected products
- Plone Plone: version 3.3 only; version 3.3.1 only; version 3.3.2 only; version 3.3.3 only; version 3.3.4 only; version 3.3.5 only; …
Published 2017-09-25. Last modified 2026-06-17.