Products.isurlinportal has possible open redirect when using more than 2 forward slashes
A url /login?came_from=////evil.example may redirect to an external website after login. Standard Plone is not affected, but if you have customised the login, for example with add-ons, you might be affected. You can try the url to check if you are affected or not.