CVE-2026-28222
- EPSS 0.1%
- Veröffentlicht 05.03.2026 18:58:20
- Zuletzt bearbeitet 09.03.2026 20:54:53
Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on rendering TableBlock blocks within a StreamField. A user with access to...
CVE-2026-28223
- EPSS 0.04%
- Veröffentlicht 05.03.2026 18:56:41
- Zuletzt bearbeitet 09.03.2026 20:54:40
Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on confirmation messages within the wagtail.contrib.simple_translation mod...
CVE-2026-25517
- EPSS 0.01%
- Veröffentlicht 04.02.2026 20:48:19
- Zuletzt bearbeitet 20.02.2026 21:20:34
Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7.3, due to a missing permission check on the preview endpoints, a user with access to the Wagtail admin and knowledge of a model's...
CVE-2025-45388
- EPSS 0.2%
- Veröffentlicht 07.05.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers can inject malicious code inside a PDF file. When a user clicks the document in the CMS interface, the payload executes. NOTE: this...
CVE-2024-35228
- EPSS 0.16%
- Veröffentlicht 30.05.2024 19:15:16
- Zuletzt bearbeitet 15.04.2026 00:35:42
Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in the `wagtail.contrib.settings` module, a user with access to the Wagtail admin and knowledge of the URL of the edit view for a setti...
CVE-2024-32882
- EPSS 0.08%
- Veröffentlicht 02.05.2024 07:15:20
- Zuletzt bearbeitet 15.04.2026 00:35:42
Wagtail is an open source content management system built on Django. In affected versions if a model has been made available for editing through the `wagtail.contrib.settings` module or `ModelViewSet`, and the `permission` argument on `FieldPanel` ha...