An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site. References: https://plone.org/security/hotfix/20200121 https://plone.org/security/hotfix/20200121/xss-in-the-title-field-on-plone-5-0-and-higher
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-7937