Description
Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Remediation
References
Related Vulnerabilities
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-28783)
Moodle Improper Access Control Vulnerability (CVE-2020-25629)
WordPress Plugin Activity Log Multiple Cross-Site Scripting Vulnerabilities (2.3.2)
phpMyFAQ Other Vulnerability (CVE-2005-3049)
Mailman Improper Input Validation Vulnerability (CVE-2018-13796)