CVE-2016-4041: Plone
High severity, CVSS 7.3. EPSS: 1.5% chance of exploitation in the next 30 days.
Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors.
Affected products
- Plone Plone: version 4.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.0.5 only; …
Published 2017-02-24. Last modified 2026-06-17.