CRITICAL
9.1 CVE-2026-55247 Published 28 Aug 2026
Plone iCalendar Import Vulnerability
Worried this affects one of your servers?
Plone's event content type, provided by plone.app.event, is vulnerable in versions prior to 5.2.4 and 6.0.1.
The iCalendar import feature accepts insufficiently restricted URLs, leading to resource exhaustion and potential script execution in other users' browsers.
Impacted Versions:
- All versions prior to 5.2.4
- All versions prior to 6.0.1
Reference: CVE-2026-55247 on NVD
← Back to Security News