Plone CMS Incorrect Permission Assignment for Critical Resource Vulnerability - CVE-2021-33509
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.
