HIGH7.1
PYSEC-2026-1797
Cross-Frame Scripting vulnerability has been found on Plone CMS
Quick fix
PYSEC-2026-1797 — plone: upgrade to the fixed version with the command below.
pip install --upgrade 'plone>=6.0.7'Details
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting version below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.
Are you affected?
Enter the version of the package you're using.