PatchSiren cyber security CVE debrief
CVE-2016-7147 Plone CVE debrief
CVE-2016-7147 is a cross-site scripting flaw in Plone's Zope ZMI search path, specifically the manage_findResult component. The record says remote attackers could inject arbitrary web script or HTML through vectors involving double quotes, with obj_ids:tokens called out as a demonstration input. NVD also ties the issue to an incomplete fix for CVE-2016-7140. The affected versions listed in the source corpus are Plone before 4.3.12 and 5.x before 5.0.7. It is not marked as a CISA KEV item in the supplied enrichment.
- Vendor
- Plone
- Product
- Unknown
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-04
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-04
- Advisory updated
- 2026-05-13
Who should care
Plone administrators, security teams, and developers maintaining affected Plone instances should care, especially where Zope ZMI search or related admin pages are used.
Technical summary
The vulnerability is a CWE-79 XSS issue in the manage_findResult component of Plone's search feature in Zope ZMI. The supplied NVD vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, which indicates network reachability and user interaction are required, with low confidentiality and integrity impact and no availability impact. The source description attributes the flaw to an incomplete fix for CVE-2016-7140 and lists vulnerable Plone versions up to 4.3.11 and 5.0.6.
Defensive priority
Medium. The issue is remotely reachable and can affect admin-facing workflows, but it requires user interaction and is scored 6.1 rather than high severity.
Recommended defensive actions
- Upgrade affected Plone installations to 4.3.12, 5.0.7, or a later fixed release.
- Review and apply the Plone hotfix/advisory referenced in the 20170117 security update.
- Audit any custom templates, search-result views, or ZMI integrations that render untrusted data in the search flow.
- Verify that the affected search path no longer reflects user-controlled input into HTML or JavaScript contexts after patching.
Evidence notes
This debrief is based on the supplied NVD record, which provides the vulnerability description, CVSS vector, CWE-79 classification, affected version entries, and reference list. The vendor advisory links on plone.org are the primary remediation references, and the description explicitly states the vulnerability exists because of an incomplete fix for CVE-2016-7140. No exploit code, weaponized reproduction, or unsupported impact claims are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-7147 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-7147
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-7147 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-7147
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://plone.org/security/hotfix/20170117
[email protected] - Patch, Release Notes, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://plone.org/security/hotfix/20170117/non-persistent-xss-in-zope2
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.curesec.com/blog/article/blog/Plone-XSS-186.html
[email protected] - Patch, Third Party Advisory, VDB Entry
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.