CRITICAL 9.1 CVE-2026-55247 Published 28 Aug 2026

Plone iCalendar Import Vulnerability

Worried this affects one of your servers?

Plone's event content type, provided by plone.app.event, is vulnerable in versions prior to 5.2.4 and 6.0.1.

The iCalendar import feature accepts insufficiently restricted URLs, leading to resource exhaustion and potential script execution in other users' browsers.

Impacted Versions:

  • All versions prior to 5.2.4
  • All versions prior to 6.0.1

Reference: CVE-2026-55247 on NVD

← Back to Security News