{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/plone/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:plone:plone_app_portlets:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-55248"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["plone.app.portlets (\u003e= 7.0.0, \u003c= 7.0.1)","plone.app.portlets (\u003e= 6.0.0, \u003c 6.0.4)","plone.app.portlets (\u003c 5.0.8)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Plone"],"content_html":"\u003cp\u003eThe Plone Security Team has identified critical security vulnerabilities (CVE-2026-55248) in the \u003ccode\u003eplone.app.portlets\u003c/code\u003e package. The vulnerabilities stem from the RSS feed portlet implementation. A user with permissions to manage portlets can provide an RSS feed URL pointing to a large file, causing significant memory consumption and leading to a denial of service (DoS). Furthermore, the lack of validation on the RSS URL allows an attacker to conduct server-side request forgery (SSRF) to probe internal network services and discover open ports. Additionally, the RSS feed parser is vulnerable to stored cross-site scripting (XSS) if a feed item contains a URL using the 'javascript:' protocol. These vulnerabilities impact Plone 6.2, 6.1, and 6.0 versions. Organizations should prioritize patching or implementing the recommended access restrictions for the portlet management feature.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could result in service instability due to memory exhaustion, unauthorized exposure of internal network topology via SSRF, and potential account takeover or unauthorized actions through stored XSS. These issues affect any organization utilizing the RSS portlet feature within Plone environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003eplone.app.portlets\u003c/code\u003e immediately to the patched versions: 7.0.2 for Plone 6.2, 6.0.4 for Plone 6.1, and 5.0.8 for Plone 6.0.\u003c/li\u003e\n\u003cli\u003eRevoke the \u003ccode\u003eplone.app.portlets.ManageOwnPortlets\u003c/code\u003e permission from untrusted roles to limit the attack surface.\u003c/li\u003e\n\u003cli\u003eAudit existing portlets to ensure no unauthorized RSS feeds are configured.\u003c/li\u003e\n\u003cli\u003eIf the RSS portlet is not required, unregister it via \u003ccode\u003eportlets.xml\u003c/code\u003e configuration to mitigate the risk entirely.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:13:28Z","date_published":"2026-08-28T21:13:28Z","id":"https://feed.craftedsignal.io/briefs/2026-08-plone-rss-vulnerability/","summary":"The plone.app.portlets package is vulnerable to denial of service, SSRF, and stored XSS via the RSS feed portlet feature, allowing authenticated users with portlet management permissions to exhaust memory, perform internal network reconnaissance, or inject malicious scripts.","title":"Critical Vulnerabilities in plone.app.portlets RSS Feed Portlet","url":"https://feed.craftedsignal.io/briefs/2026-08-plone-rss-vulnerability/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:plone:plone.app.event:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-55247"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["plone.app.event (vulnerable: \u003c 5.2.4)","plone.app.event (vulnerable: \u003e= 6.0.0a1, \u003c 6.0.1)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Plone"],"content_html":"\u003cp\u003eThe plone.app.event package, a component used within the Plone content management system, is affected by a series of vulnerabilities (CVE-2026-55247) originating in its iCalendar import functionality. The flaws allow a logged-in editor to conduct a denial-of-service attack, perform Server-Side Request Forgery (SSRF) to read internal network resources or local server files, and execute stored Cross-Site Scripting (XSS) via the event URL field. These vulnerabilities were responsibly reported and patched in versions 5.2.4 and 6.0.1. Due to the nature of the SSRF and DoS vectors, environments where untrusted users possess the 'Editor' role are at high risk of internal reconnaissance and service disruption. There is currently no known workaround for the stored XSS vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could result in total site unavailability, exfiltration of internal network or local file system data via SSRF, and persistent XSS injection. These vulnerabilities target the administrative and content creation workflows of Plone installations, putting any organization relying on Plone for public or internal content hosting at risk of data breach or operational outages.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize upgrading plone.app.event to the patched versions: 6.0.1 for Plone 6.2 users, or 5.2.4 for Plone 6.0 and 6.1 users.\u003c/li\u003e\n\u003cli\u003eUntil patching is complete, restrict the \u0026quot;plone.app.event: Import Ical\u0026quot; permission exclusively to the \u0026quot;Manager\u0026quot; role within the Zope Management Interface (manage_access) to limit the attack surface to trusted administrators.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous POST requests to calendar import endpoints or requests targeting internal network or local file paths.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:13:20Z","date_published":"2026-08-28T21:13:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-plone-event-vulnerability/","summary":"The plone.app.event package contains multiple vulnerabilities including DoS, SSRF, and stored XSS within its iCalendar import functionality, potentially allowing a logged-in editor to compromise server availability and security.","title":"Critical Vulnerabilities in plone.app.event","url":"https://feed.craftedsignal.io/briefs/2026-08-plone-event-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Plone","version":"https://jsonfeed.org/version/1.1"}