CVE-2026-55247: Plone Plone.app.event
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in editor can make the server request internal network resources or local calendar files, exhaust resources and take the site offline, and store a malicious event URL that executes script in another user's browser. The fix restricts accepted URLs, applies MAXIMUM_ICAL_IMPORT_SIZE_BYTES and MAXIMUM_ICAL_IMPORT_EVENTS limits, uses transaction savepoints, and validates event URLs. This issue is fixed in versions 5.2.4 and 6.0.1.
Affected products
- Plone Plone.app.event: before 5.2.4 (fixed in 5.2.4); from 6.0.0, before 6.0.1 (fixed in 6.0.1)
Published 2026-08-28. Last modified 2026-09-09.