CVE-2015-7317: Kupu Project Kupu

Medium severity, CVSS 6.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 allows remote authenticated users to edit Kupu settings.

Affected products

  • Kupu Project Kupu: up to and including 1.4.16
  • Plone Plone: version 3.3 only; version 3.3.1 only; version 3.3.2 only; version 3.3.3 only; version 3.3.4 only; version 3.3.5 only; …

Published 2017-09-25. Last modified 2026-06-17.