Cyber Resilience

CVE-2024-23756

Plone 5.2.13

Public PoC
Published
08 February 2024
Modified
17 June 2026
CVSS Score v3.1 7.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score 0.0060 46th percentile
Risk Priority 58 floored blend · peak EPSS

Summary

CVE-2024-23756 is a high-severity an unspecified weakness vulnerability in Plone Plone. Its CVSS base score is 7.5 (High).

Operationally, ranked at the 46th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-0669Same product: Plone Plone
CVE-2024-22889Same product: Plone Plone
CVE-2023-41048Same product: Plone Plone
CVE-2024-23054Same vendor: Plone
CVE-2023-42457Same vendor: Plone
CVE-2026-28413Same vendor: Plone
CVE-2024-23055Same vendor: Plone

Affected Assets

plone
plone
5.2.13

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References