CVE-2016-4043: Plone

Medium severity, CVSS 4.9. EPSS: 1% chance of exploitation in the next 30 days.

Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.

Affected products

  • Plone Plone: version 5.0 only; version 5.0.1 only; version 5.0.2 only; version 5.0.3 only; version 5.0.4 only; version 5.1a1 only

Published 2017-02-24. Last modified 2026-06-17.