Wagtail wagtail是Wagtail组织的内容管理系统。 Wagtail存在权限许可和访问控制问题漏洞,该漏洞源于图像预览端点缺少权限检查,可能导致具有Wagtail管理员访问权限的用户预览任意图像。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54263 | 7.3 HIGH | Wagtail: Reflected XSS in dynamic image URL generator view |
| CVE-2026-54262 | 4.3 MEDIUM | Wagtail: Pages translations can be created without page permissions when using simple_tran |
| CVE-2026-54260 | 4.3 MEDIUM | Wagtail: Denial of service via unbounded filter specs in the image preview |
| CVE-2026-54259 | 4.3 MEDIUM | Wagtail: Improper restriction handling on Documents and Images chosen endpoints |
No comments yet