Plone 5.2
Plone 5.2
The Plone 5.2 reached end of service life on Oct 31, 2024 — Plone no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Plone 5.2 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- plone
- release
- 5.2
- product Label
- Plone
- release Label
- 5.2
- codename
- lts
- latest Version
- 5.2.15
- release Date
- 2019-07-10
- maintained
- source Url
- https://endoflife.date/plone
Lifecycle Dates
- End of Service Life
- Oct 31, 2024
- Last OEM Support
- Oct 31, 2023
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Plone 5.2 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Plone 5.2?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Plone 5.2 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Plone 5.2 Support: Frequently Asked Questions
Is the Plone 5.2 still supported?
Plone ended support for the Plone 5.2 on Oct 31, 2024 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Plone 5.2 end of service life (EOSL) date?
Plone lists the end of service life for the Plone 5.2 as Oct 31, 2024.
Can I keep using the Plone 5.2 after its EOSL date?
Yes. EOSL means Plone stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Plone 5.2 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Plone 5.2
24 published CVEs affect the Plone 5.2, including 11 rated critical or high severity. Plone no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2021-33509 | CRITICAL | 9.9 | May 21, 2021 | Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script. |
| CVE-2020-7941 | CRITICAL | 9.8 | Jan 23, 2020 | A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission. |
| CVE-2021-33926 | HIGH | 8.8 | Feb 17, 2023 | An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7, 4.3.6, 4.3.5, 4.3.4, 4.3.3, 4.3.20, 4 allows attacker to access sensitive information via the RSS feed protlet. |
| CVE-2020-28736 | HIGH | 8.8 | Dec 30, 2020 | Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role). |
| CVE-2020-28735 | HIGH | 8.8 | Dec 30, 2020 | Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role). |
| CVE-2020-28734 | HIGH | 8.8 | Dec 30, 2020 | Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role. |
| CVE-2020-7939 | HIGH | 8.8 | Jan 23, 2020 | SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.) |
| CVE-2020-7938 | HIGH | 8.8 | Jan 23, 2020 | plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level. |
| CVE-2024-23756 | HIGH | 7.5 | Feb 8, 2024 | The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them. |
| CVE-2021-33511 | HIGH | 7.5 | May 21, 2021 | Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel. |
| CVE-2020-7940 | HIGH | 7.5 | Jan 23, 2020 | Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking. |
| CVE-2021-32633 | MEDIUM | 6.8 | May 21, 2021 | Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules indirectly through Python modules that are available for direct use. By default, only users with the Manager role can add or edit Zope Page Templates through the web, but sites that allow untrusted users to add/edit Zope Page Templates through the web are at risk from this vulnerability. The problem has been fixed in Zope 5.2 and 4.6. As a workaround, a site administrator can |
| CVE-2021-21336 | MEDIUM | 6.5 | Mar 8, 2021 | Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an information disclosure vulnerability - everyone can list the names of roles defined in the ZODB Role Manager plugin if the site uses this plugin. The problem has been fixed in version 2.6.0. Depending on how you have installed Products.PluggableAuthService, you should change the buildout version pin to 2.6.0 and re-run the buildout, or if |
| CVE-2024-0669 | MEDIUM | 6.3 | Jan 18, 2024 | A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element. |
| CVE-2021-33507 | MEDIUM | 6.1 | May 21, 2021 | Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS. |
| CVE-2020-7936 | MEDIUM | 6.1 | Jan 23, 2020 | An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site. |
| CVE-2021-35959 | MEDIUM | 5.4 | Jun 30, 2021 | In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field. |
| CVE-2021-33513 | MEDIUM | 5.4 | May 21, 2021 | Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool. |
| CVE-2021-33512 | MEDIUM | 5.4 | May 21, 2021 | Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document. |
| CVE-2021-33508 | MEDIUM | 5.4 | May 21, 2021 | Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item. |
Showing the 20 most severe of 24 known CVEs.
Get Third Party Support