<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Plone.app.portlets (&lt; 5.0.8) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/plone.app.portlets--5.0.8/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 28 Aug 2026 21:13:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/plone.app.portlets--5.0.8/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in plone.app.portlets RSS Feed Portlet</title><link>https://feed.craftedsignal.io/briefs/2026-08-plone-rss-vulnerability/</link><pubDate>Fri, 28 Aug 2026 21:13:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-plone-rss-vulnerability/</guid><description>The plone.app.portlets package is vulnerable to denial of service, SSRF, and stored XSS via the RSS feed portlet feature, allowing authenticated users with portlet management permissions to exhaust memory, perform internal network reconnaissance, or inject malicious scripts.</description><content:encoded><![CDATA[<p>The Plone Security Team has identified critical security vulnerabilities (CVE-2026-55248) in the <code>plone.app.portlets</code> package. The vulnerabilities stem from the RSS feed portlet implementation. A user with permissions to manage portlets can provide an RSS feed URL pointing to a large file, causing significant memory consumption and leading to a denial of service (DoS). Furthermore, the lack of validation on the RSS URL allows an attacker to conduct server-side request forgery (SSRF) to probe internal network services and discover open ports. Additionally, the RSS feed parser is vulnerable to stored cross-site scripting (XSS) if a feed item contains a URL using the 'javascript:' protocol. These vulnerabilities impact Plone 6.2, 6.1, and 6.0 versions. Organizations should prioritize patching or implementing the recommended access restrictions for the portlet management feature.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation could result in service instability due to memory exhaustion, unauthorized exposure of internal network topology via SSRF, and potential account takeover or unauthorized actions through stored XSS. These issues affect any organization utilizing the RSS portlet feature within Plone environments.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade <code>plone.app.portlets</code> immediately to the patched versions: 7.0.2 for Plone 6.2, 6.0.4 for Plone 6.1, and 5.0.8 for Plone 6.0.</li>
<li>Revoke the <code>plone.app.portlets.ManageOwnPortlets</code> permission from untrusted roles to limit the attack surface.</li>
<li>Audit existing portlets to ensure no unauthorized RSS feeds are configured.</li>
<li>If the RSS portlet is not required, unregister it via <code>portlets.xml</code> configuration to mitigate the risk entirely.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>