VDB
Sign up
MEDIUM5.4

PYSEC-2026-2962

Products.CMFPlone XSS in profile home_page property

Quick fix

PYSEC-2026-2962 — products-cmfplone: upgrade to the fixed version with the command below.

pip install --upgrade 'products-cmfplone>=4.3.17'

Details

A member of the Plone site could set javascript in the `home_page` property of their profile, and have this executed when a visitor clicks the home page link on the author page.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/products-cmfplone
Introduced in: 0Fixed in: 4.3.17
Fixpip install --upgrade 'products-cmfplone>=4.3.17'

References