django CMS 是一个基于 Django 构建的、易于使用且对开发者友好的企业内容管理系统。在 5.0.8 版本之前,cms/admin/placeholderadmin.py 中的 copy_plugins 端点仅对目标剪贴板进行了授权校验。_copy_plugin_to_clipboard 和 _copy_placeholder_to_clipboard 接口虽然接受了 source_placeholder_id 和 source_plugin_id 参数,但在使用 has_copy_plugins_pe
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| django-cms | django-cms | < 5.0.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| django-cms | django-cms | < 5.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54623 | 7.1 HIGH | django CMS: Plugin move endpoint allows cyclic reparenting (DoS) |
| CVE-2026-54624 | 6.5 MEDIUM | django CMS: Structure endpoint bypasses page-view permission |
| CVE-2026-63003 | 6.5 MEDIUM | django CMS: Broken access control in page *Duplicate* allows reading the content of any pa |
| CVE-2026-54625 | 4.8 MEDIUM | django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) |
| CVE-2026-75526 | 4.4 MEDIUM | django CMS: Stored XSS in edit-mode plugin exception rendering |
| CVE-2026-61663 | 4.3 MEDIUM | django CMS: Missing authorization in `render_object_structure` discloses non-PageContent p |
No comments yet