
CVE-2026-28413 Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redi… https://www.cve.org/CVERecord?id=CVE-2026-28413
Post summary
CVE-2026-28413 is a vulnerability in Plone’s Products.isurlinportal where manipulating the /login?came_from parameter can result in a redirect, affecting versions before 2.1.0, 3.1.0, and 4.0.0.

