Security

All about Plone's baked-in security

Security update policy

by Paul Roeland — last modified May 15, 2016 09:22 AM
Plone's security team releases regular updates every four months. These fixes almost exclusively contain fixes and security improvements found by the security team's audits.

Available hotfixes

by Paul Roeland — last modified May 15, 2016 09:52 AM
There may be hotfixes applicable to your version of Plone. Always check the Plone Hotfix Page before production deployment.

Security track record

by Paul Roeland — last modified May 15, 2016 09:26 AM
Measuring or quantifying security risks in software is hard — security is a process, not a product, and thus requires constant vigilance and good coding practices combined with security reviews. Yet we have never received a report of a serious vulnerability in Plone being exploited in the wild.