Remote Code Execution via traversal in TAL expressions
Modified: 7/9/2026
package
pkg:pypi/zope
Remote Code Execution via traversal in TAL expressions
Modified: 7/9/2026
ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions
Modified: 7/6/2026
Zope allows attackers to modify raw image and file data
Modified: 7/6/2026
Information disclosure in AccessControl
Modified: 7/13/2026
Zope does not properly restrict access to the getRoles method
Modified: 7/6/2026
Zope does not properly verify the access for objects with proxy roles
Modified: 7/6/2026
Remote Code Execution via Script (Python) objects under Python 3
Modified: 7/9/2026
Access control vulnerable to user data deletion by anonynmous users
Modified: 7/13/2026
Zope does not properly perform security registration for legacy names
Modified: 7/6/2026
Zope DocumentTemplate package allows unauthenticated write
Modified: 7/6/2026
Zope management interface vulnerable to stored cross site scripting via the title property
Modified: 9/10/2026
Remote Code Execution via unsafe classes in otherwise permitted modules
Modified: 7/9/2026
Zope Denial of Service (DoS) vulnerability in ZServer
Modified: 7/9/2026
Remote Code Execution via traversal in TAL expressions
Modified: 7/9/2026
Zope XSS Vulnerability
Modified: 7/13/2026
Zope Server vulnerable to DoS via header injection
Modified: 7/6/2026
Zope DTML implementation Improper Authentication
Modified: 7/6/2026
Zope vulnerable to Stored Cross Site Scripting with SVG images
Modified: 9/10/2026
Modified: 7/9/2026
Modified: 7/9/2026
Modified: 7/9/2026
Modified: 7/9/2026
Modified: 7/9/2026
Modified: 11/8/2023
Information disclosure in AccessControl
Modified: 7/13/2026
Access control vulnerable to user data deletion by anonynmous users
Modified: 7/13/2026
Zope vulnerable to Stored Cross Site Scripting with SVG images
Modified: 7/7/2026
Zope XSS Vulnerability
Modified: 7/13/2026
ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions
Modified: 7/6/2026
Zope allows attackers to modify raw image and file data
Modified: 7/6/2026
Zope does not properly restrict access to the getRoles method
Modified: 7/6/2026
Zope does not properly verify the access for objects with proxy roles
Modified: 7/6/2026
Zope does not properly perform security registration for legacy names
Modified: 7/6/2026
Zope DocumentTemplate package allows unauthenticated write
Modified: 7/6/2026
Zope Server vulnerable to DoS via header injection
Modified: 7/6/2026
Zope DTML implementation Improper Authentication
Modified: 7/6/2026