django CMS 是一个易用且对开发者友好的企业级内容管理系统,由 Django 驱动。在 5.0.8 版本之前,cms/views.py 中的 render_object_structure 函数在渲染 PageContent 对象的 cms/toolbar/structure.html 模板时,未调用 user_can_view_page() 进行权限校验。当启用 CMS_PERMISSION 配置,且页面设置了视图权限限制,或 CMS_PUBLIC_FOR 被设置为 staff 时,任何拥有 staff
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| django-cms | django-cms | < 5.0.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| django-cms | django-cms | < 5.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54623 | 7.1 HIGH | django CMS: Plugin move endpoint allows cyclic reparenting (DoS) |
| CVE-2026-54622 | 6.5 MEDIUM | django CMS: Clipboard copy IDOR discloses unauthorized plugin content |
| CVE-2026-63003 | 6.5 MEDIUM | django CMS: Broken access control in page *Duplicate* allows reading the content of any pa |
| CVE-2026-54625 | 4.8 MEDIUM | django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) |
| CVE-2026-75526 | 4.4 MEDIUM | django CMS: Stored XSS in edit-mode plugin exception rendering |
| CVE-2026-61663 | 4.3 MEDIUM | django CMS: Missing authorization in `render_object_structure` discloses non-PageContent p |
No comments yet