CVE-2026-44198
- EPSS 0.16%
- Veröffentlicht 11.05.2026 16:17:35
- Zuletzt bearbeitet 12.05.2026 15:58:41
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could still access the history report for the page, potentially resulting in disclosure of sensitive in...
CVE-2026-44199
- EPSS 0.17%
- Veröffentlicht 11.05.2026 16:17:35
- Zuletzt bearbeitet 12.05.2026 15:58:28
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form pages they don't have access to by crafting a form submission to delete...
CVE-2026-44200
- EPSS 0.2%
- Veröffentlicht 11.05.2026 16:17:35
- Zuletzt bearbeitet 12.05.2026 15:57:27
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once coped, they'd be able to vie...
CVE-2026-44201
- EPSS 0.26%
- Veröffentlicht 11.05.2026 16:17:35
- Zuletzt bearbeitet 12.05.2026 15:59:06
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A user with access to the API could see the filename and name of docume...
CVE-2026-44197
- EPSS 0.2%
- Veröffentlicht 11.05.2026 16:17:34
- Zuletzt bearbeitet 12.05.2026 15:58:58
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the page through the revision compare view if they knew the primary key of tw...
CVE-2026-28222
- EPSS 0.42%
- Veröffentlicht 05.03.2026 18:58:20
- Zuletzt bearbeitet 09.03.2026 20:54:53
Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on rendering TableBlock blocks within a StreamField. A user with access to...
CVE-2026-28223
- EPSS 0.46%
- Veröffentlicht 05.03.2026 18:56:41
- Zuletzt bearbeitet 09.03.2026 20:54:40
Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on confirmation messages within the wagtail.contrib.simple_translation mod...
CVE-2026-25517
- EPSS 0.34%
- Veröffentlicht 04.02.2026 20:48:19
- Zuletzt bearbeitet 20.02.2026 21:20:34
Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7.3, due to a missing permission check on the preview endpoints, a user with access to the Wagtail admin and knowledge of a model's...
CVE-2025-45388
- EPSS 0.25%
- Veröffentlicht 07.05.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers can inject malicious code inside a PDF file. When a user clicks the document in the CMS interface, the payload executes. NOTE: this...
CVE-2024-35228
- EPSS 0.33%
- Veröffentlicht 30.05.2024 19:15:16
- Zuletzt bearbeitet 15.04.2026 00:35:42
Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in the `wagtail.contrib.settings` module, a user with access to the Wagtail admin and knowledge of the URL of the edit view for a setti...