Skip to main content

Vendor/product archive

torchbox / wagtail CVEs

Beta · best-effort

23 CVEs tagged to torchbox / wagtail0 Critical, 1 High, 20 Medium, 2 Low, 0 Unrated.

CVE-2026-54263

Published Jul 1, 2026

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflected cross-site scripting (XSS) vulnerability exists on the…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54262

Published Jul 1, 2026

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54261

Published Jul 1, 2026

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint,…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54260

Published Jul 1, 2026

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an authenticated admin user can trigger expensive rendition proce…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54259

Published Jul 1, 2026

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly li…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44201

Published May 11, 2026

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections.…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44200

Published May 11, 2026

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have acce…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44199

Published May 11, 2026

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44198

Published May 11, 2026

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could still access the history r…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44197

Published May 11, 2026

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the pa…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28223

Published Mar 5, 2026

Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on…

CVSS 6.1 · Medium
evidence mentions
9
Buzz score
28.0
Vendor/product tagsBeta · best-effort

CVE-2026-28222

Published Mar 5, 2026

Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on…

CVSS 6.1 · Medium
evidence mentions
9
Buzz score
28.0
Vendor/product tagsBeta · best-effort

CVE-2026-25517

Published Feb 4, 2026

Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7.3, due to a missing permission check on the preview endpoi…

CVSS 5.1 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2024-39317

Published Jul 11, 2024

Wagtail is an open source content management system built on Django. A bug in Wagtail's `parse_query_string` would result in it taking a long time to process suitably crafted inpu…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45809

Published Oct 19, 2023

Wagtail is an open source content management system built on Django. A user with a limited-permission editor account for the Wagtail admin can make a direct URL request to the adm…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-28837

Published Apr 3, 2023

Wagtail is an open source content management system built on Django. Prior to versions 4.1.4 and 4.2.2, a memory exhaustion bug exists in Wagtail's handling of uploaded images and…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28836

Published Apr 3, 2023

Wagtail is an open source content management system built on Django. Starting in version 1.5 and prior to versions 4.1.4 and 4.2.2, a stored cross-site scripting (XSS) vulnerabili…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21683

Published Jan 18, 2022

Wagtail is a Django based content management system focused on flexibility and user experience. When notifications for new replies in comment threads are sent, they are sent to al…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-32681

Published Jun 17, 2021

Wagtail is an open source content management system built on Django. A cross-site scripting vulnerability exists in versions 2.13-2.13.1, versions 2.12-2.12.4, and versions prior…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29434

Published Apr 19, 2021

Wagtail is a Django content management system. In affected versions of Wagtail, when saving the contents of a rich text field in the admin interface, Wagtail does not apply server…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15118

Published Jul 20, 2020

In Wagtail before versions 2.7.4 and 2.9.3, when a form page type is made available to Wagtail editors through the `wagtail.contrib.forms` app, and the page template is built usin…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11037

Published Apr 30, 2020

In Wagtail before versions 2.7.3 and 2.8.2, a potential timing attack exists on pages or documents that have been protected with a shared password through Wagtail's "Privacy" cont…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11001

Published Apr 14, 2020

In Wagtail before versions 2.8.1 and 2.7.2, a cross-site scripting (XSS) vulnerability exists on the page revision comparison view within the Wagtail admin interface. A user with…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1