{"id":"CVE-2020-7937","aliases":["GHSA-8mc4-2xrc-g582","PYSEC-2020-86"],"url":"https://o3.security/vulnerability/CVE-2020-7937","summary":"Plone cross site scripting (XSS)","details":"An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site.","published":"2020-01-23T21:15:13.270Z","modified":"2026-07-08T17:56:59.370034Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00809,"percentile":0.53742,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"plone","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2020/01/24/1"},{"type":"ADVISORY","url":"https://plone.org/security/hotfix/20200121"},{"type":"ADVISORY","url":"https://plone.org/security/hotfix/20200121/xss-in-the-title-field-on-plone-5-0-and-higher"},{"type":"ADVISORY","url":"https://www.openwall.com/lists/oss-security/2020/01/22/1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T17:56:59.370034Z"}}