CVE-2026-44201
- EPSS 0.26%
- Veröffentlicht 11.05.2026 16:17:35
- Zuletzt bearbeitet 12.05.2026 15:59:06
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A user with access to the API could see the filename and name of docume...
CVE-2026-44200
- EPSS 0.2%
- Veröffentlicht 11.05.2026 16:17:35
- Zuletzt bearbeitet 12.05.2026 15:57:27
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once coped, they'd be able to vie...
CVE-2026-44199
- EPSS 0.17%
- Veröffentlicht 11.05.2026 16:17:35
- Zuletzt bearbeitet 12.05.2026 15:58:28
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form pages they don't have access to by crafting a form submission to delete...
CVE-2026-44198
- EPSS 0.16%
- Veröffentlicht 11.05.2026 16:17:35
- Zuletzt bearbeitet 12.05.2026 15:58:41
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could still access the history report for the page, potentially resulting in disclosure of sensitive in...
CVE-2026-44197
- EPSS 0.2%
- Veröffentlicht 11.05.2026 16:17:34
- Zuletzt bearbeitet 12.05.2026 15:58:58
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the page through the revision compare view if they knew the primary key of tw...
CVE-2026-28222
- EPSS 0.42%
- Veröffentlicht 05.03.2026 18:58:20
- Zuletzt bearbeitet 09.03.2026 20:54:53
Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on rendering TableBlock blocks within a StreamField. A user with access to...
CVE-2026-28223
- EPSS 0.46%
- Veröffentlicht 05.03.2026 18:56:41
- Zuletzt bearbeitet 09.03.2026 20:54:40
Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on confirmation messages within the wagtail.contrib.simple_translation mod...
CVE-2026-25517
- EPSS 0.34%
- Veröffentlicht 04.02.2026 20:48:19
- Zuletzt bearbeitet 20.02.2026 21:20:34
Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7.3, due to a missing permission check on the preview endpoints, a user with access to the Wagtail admin and knowledge of a model's...
CVE-2024-39317
- EPSS 0.61%
- Veröffentlicht 11.07.2024 16:15:02
- Zuletzt bearbeitet 20.03.2026 18:34:00
Wagtail is an open source content management system built on Django. A bug in Wagtail's `parse_query_string` would result in it taking a long time to process suitably crafted inputs. When used to parse sufficiently long strings of characters without ...
CVE-2023-45809
- EPSS 0.45%
- Veröffentlicht 19.10.2023 19:15:15
- Zuletzt bearbeitet 21.11.2024 08:27:23
Wagtail is an open source content management system built on Django. A user with a limited-permission editor account for the Wagtail admin can make a direct URL request to the admin view that handles bulk actions on user accounts. While authenticatio...