CVE-2026-75526
- EPSS -
- Veröffentlicht 20.08.2026 18:11:10
- Zuletzt bearbeitet 20.08.2026 20:17:46
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled values to ContentRe...
CVE-2026-63003
- EPSS -
- Veröffentlicht 20.08.2026 18:09:13
- Zuletzt bearbeitet 20.08.2026 19:16:57
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on the source page. In cms/admin/forms.py, DuplicatePageForm.source...
CVE-2026-61663
- EPSS -
- Veröffentlicht 20.08.2026 18:07:28
- Zuletzt bearbeitet 20.08.2026 19:16:56
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, render_object_structure fails to authorize non-PageContent objects that use PlaceholderRelationField. An active staff user wit...
CVE-2026-54622
- EPSS -
- Veröffentlicht 20.08.2026 18:06:00
- Zuletzt bearbeitet 20.08.2026 19:16:55
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the copy_plugins endpoint in cms/admin/placeholderadmin.py authorizes only the destination clipboard. The _copy_plugin_to_clip...
CVE-2026-54624
- EPSS -
- Veröffentlicht 20.08.2026 18:04:38
- Zuletzt bearbeitet 20.08.2026 20:17:35
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, render_object_structure in cms/views.py renders cms/toolbar/structure.html for a PageContent object without calling user_can_v...
CVE-2026-54623
- EPSS -
- Veröffentlicht 20.08.2026 18:02:45
- Zuletzt bearbeitet 20.08.2026 19:16:55
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value without rejecting...
CVE-2026-54625
- EPSS -
- Veröffentlicht 20.08.2026 17:58:03
- Zuletzt bearbeitet 20.08.2026 20:17:35
django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes ...
CVE-2024-11319
- EPSS 0.5%
- Veröffentlicht 18.11.2024 12:15:17
- Zuletzt bearbeitet 02.06.2026 07:16:12
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS). This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.
CVE-2021-44649
- EPSS 0.62%
- Veröffentlicht 12.01.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:31:18
Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript cod...
CVE-2015-5081
- EPSS 1.04%
- Veröffentlicht 18.08.2017 18:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
Cross-site request forgery (CSRF) vulnerability in django CMS before 3.0.14, 3.1.x before 3.1.1 allows remote attackers to manipulate privileged users into performing unknown actions via unspecified vectors.