Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wagtail — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in wagtail, with AI-generated Chinese analysis, references, and POCs.

This page documents common weaknesess associated with the Wagtail content management system produced by the Wagtail project team. It aggregates reported security vulnerabilities affecting versions of this open-source Django-based CMS, covering data ranging from initial public disclosures through to recently patched issues. The collection focuses on flaws such as cross-site scripting, authentication bypasses, and improper access controls that have been identified within the codebase or its plugins. Visitors can utilize this resource to track vendor advisories issued by the maintainers and community contributors, understand the characteristics and impact of specific weakness classes within this technology stack, and look up a product's vulnerability history to assess risk over time. The information is organized to help security professionals, developers, and system administrators identify which components are affected and determine the urgency of applying updates. By centralizing these records, the page serves as a reference point for understanding the security posture of Wagtail instances. Users can search by version number or vulnerability type to find relevant details without needing to scour multiple external sources. This consolidated view aids in maintaining secure deployments by highlighting known issues that require mitigation through configuration changes or software upgrades. The data reflects reports from various disclosure channels, including GitHub repositories and security mailing lists, ensuring a comprehensive overview of the threat landscape for this specific product.

Vendor: wagtail

CVE IDTitleCVSSSeverityPublished
CVE-2026-54263 Wagtail: Reflected XSS in dynamic image URL generator view CWE-79 7.3 High2026-07-01
CVE-2026-54262 Wagtail: Pages translations can be created without page permissions when using simple_translation CWE-280 4.3 Medium2026-07-01
CVE-2026-54261 Wagtail: Improper permission handling in image preview CWE-280 6.5 Medium2026-07-01
CVE-2026-54259 Wagtail: Improper restriction handling on Documents and Images chosen endpoints CWE-280 4.3 Medium2026-07-01
CVE-2026-54260 Wagtail: Denial of service via unbounded filter specs in the image preview CWE-400 4.3 Medium2026-07-01
CVE-2026-44201 Wagtail: Improper restriction handling on Documents and Images API CWE-280 5.3 Medium2026-05-11
CVE-2026-44200 Wagtail: Improper permission handling when copying pages CWE-280 6.5 Medium2026-05-11
CVE-2026-44199 Wagtail: Improper permission handling when deleting form submissions CWE-280 6.5 Medium2026-05-11
CVE-2026-44198 Wagtail: Improper permission handling when viewing page history CWE-280 4.3 Medium2026-05-11
CVE-2026-44197 Wagtail: Improper permission handling when comparing revisions CWE-280 6.5 Medium2026-05-11
CVE-2026-28222 Wagtail: Improper escaping of HTML (Cross-site Scripting) on TableBlock class attributes CWE-79 6.1 Medium2026-03-05
CVE-2026-28223 Wagtail: Improper escaping of HTML (Cross-site Scripting) in simple_translation admin interface CWE-79 6.1 Medium2026-03-05
CVE-2026-25517 Wagtail has improper permission handling on admin preview endpoints CWE-862 5.3AIMediumAI2026-02-04
CVE-2024-39317 Wagtail regular expression denial-of-service via search query parsing CWE-1333 6.5 Medium2024-07-11
CVE-2024-35228 Improper Handling of Insufficient Permissions in Wagtail CWE-280 5.5 Medium2024-05-30
CVE-2024-32882 Permission check bypass when editing a model with per-field restrictions in wagtail CWE-280 2.7 Low2024-05-02
CVE-2023-45809 Disclosure of user names via admin bulk action views in wagtail CWE-200 2.7 Low2023-10-19
CVE-2023-28837 Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files CWE-400 4.9 Medium2023-04-03
CVE-2023-28836 Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views CWE-79 6.4 Medium2023-04-03
CVE-2022-21683 Comment reply notifications sent to incorrect users in wagtail CWE-200 3.5 Low2022-01-18
CVE-2021-32681 Improper escaping of HTML ('Cross-site Scripting') in Wagtail StreamField blocks CWE-79 5.4 Medium2021-06-17
CVE-2021-29434 Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields CWE-79 6.1 Medium2021-04-19
CVE-2020-15118 Cross-Site Scripting in Wagtail CWE-79 5.7 Medium2020-07-20
CVE-2020-11037 Potential Observable Timing Discrepancy in Wagtail CWE-208 6.1 Medium2020-04-30
CVE-2020-11001 Possible XSS attack in Wagtail CWE-80 5.8 Medium2020-04-14

All 25 known CVE vulnerabilities affecting wagtail with full Chinese analysis, references, and POCs where available.