Wagtail wagtail是Wagtail组织的内容管理系统。 Wagtail存在权限许可和访问控制问题漏洞,该漏洞源于Documents and Images选择器的chosen端点错误地列出了用户未被授予选择权限的项目,具有Wagtail管理访问权限的用户可查看这些集合中的文件名、名称和URL。以下版本受到影响:7.0.8之前版本、7.3.3之前版本和7.4.2之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54263 | 7.3 HIGH | Wagtail: Reflected XSS in dynamic image URL generator view |
| CVE-2026-54261 | 6.5 MEDIUM | Wagtail: Improper permission handling in image preview |
| CVE-2026-54262 | 4.3 MEDIUM | Wagtail: Pages translations can be created without page permissions when using simple_tran |
| CVE-2026-54260 | 4.3 MEDIUM | Wagtail: Denial of service via unbounded filter specs in the image preview |
No comments yet