Wagtail wagtail是Wagtail组织的内容管理系统。 Wagtail存在跨站脚本漏洞,该漏洞源于动态图像URL生成器视图存在反射型跨站脚本问题,可能导致具有有限权限的编辑器账户用户特制URL,当高权限用户查看时,以该用户凭据执行操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-54261 | 6.5 MEDIUM | Wagtail: Improper permission handling in image preview |
| CVE-2026-54262 | 4.3 MEDIUM | Wagtail: Pages translations can be created without page permissions when using simple_tran |
| CVE-2026-54260 | 4.3 MEDIUM | Wagtail: Denial of service via unbounded filter specs in the image preview |
| CVE-2026-54259 | 4.3 MEDIUM | Wagtail: Improper restriction handling on Documents and Images chosen endpoints |
No comments yet