Plone CMS Server-Side Request Forgery (SSRF) Vulnerability - CVE-2021-33511
Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes Dexterity TTW schemas and modeleditors in plone.app.theming plone.app.dexterity and plone.supermodel.