CVE-2024-0669: Plone

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.

Affected products

  • Plone Plone: before 6.0.7 (fixed in 6.0.7)

Published 2024-01-18. Last modified 2026-06-17.