CVE-2026-28413: Plone Isurlinportal
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redirect to an external website after login. This issue has been patched in versions 2.1.0, 3.1.0, and 4.0.0.
Affected products
- Plone Isurlinportal: before 2.1.0 (fixed in 2.1.0); from 3.0.0, before 3.1.0 (fixed in 3.1.0); version 4.0.0 only
Published 2026-03-05. Last modified 2026-06-17.