A critical vulnerability affecting plone.app.event versions >= 6.0.0a1, < 6.0.1, identified as CVE-2026-55247 with a CVSS score of 9.1, exists in plone.app.event that allows for denial of service via iCalendar import, stored XSS, and server-side request forgery (SSRF). A logged-in editor can exploit this flaw by abusing the iCalendar import functionality, taking the whole site offline, making the server reach into the internal network to read calendar files off disk, and storing XSS. This vulnerability affects versions prior to plone.app.event 5.2.4 for Plone 6.0 and prior to plone.app.event 6.0.1 for Plone 6.2, with no workaround available for stored XSS in the URL field of events. The flaw type is CWE-400, and the attack vector is network-based (AV:N). This vulnerability has a significant business impact as it can lead to data breaches and system compromise, resulting in financial losses and damage to reputation.
We recommend you to upgrade Plone to version 5.2.4 or 6.0.1.[/subscribe_to_unlock_form]
A critical vulnerability affecting plone.app.event versions >= 6.0.0a1, < 6.0.1, identified as CVE-2026-55247 with a CVSS score of 9.1, exists in plone.app.event that allows for denial of service via iCalendar import, stored XSS, and server-side request forgery (SSRF). A logged-in editor can exploit this flaw by abusing the iCalendar import functionality, taking the whole site offline, making the server reach into the internal network to read calendar files off disk, and storing XSS. This vulnerability affects versions prior to plone.app.event 5.2.4 for Plone 6.0 and prior to plone.app.event 6.0.1 for Plone 6.2, with no workaround available for stored XSS in the URL field of events. The flaw type is CWE-400, and the attack vector is network-based (AV:N). This vulnerability has a significant business impact as it can lead to data breaches and system compromise, resulting in financial losses and damage to reputation.
We recommend you to upgrade Plone to version 5.2.4 or 6.0.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]