wagtail vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-JM5P-837G-RV8GMediumwagtail: Wagtail: Improper restriction handling on Page translation API endpointGHSA-X5CX-W6P2-MXF2Mediumwagtail: Wagtail: Improper permission handling when copying snippetsGHSA-C2XX-CJMH-9Q8FMediumwagtail: Wagtail: Improper restriction handling on descendant collections in Documents and Images APIGHSA-92HV-J533-69WCLowwagtail: Wagtail: Identification of documents by SHA1 hashCVE-2026-55468Mediumwagtail: Wagtail: Improper restriction handling on Pages admin APICVE-2026-54263Highwagtail: Wagtail: Reflected XSS in dynamic image URL generator viewCVE-2026-54262Mediumwagtail: Wagtail: Pages translations can be created without page permissions when using simple_translationCVE-2026-54261Mediumwagtail: Wagtail: Improper permission handling in image previewCVE-2026-54260Mediumwagtail: Wagtail: Denial of service via unbounded filter specs in the image previewCVE-2026-54259Mediumwagtail: Wagtail: Improper restriction handling on Documents and Images chosen endpointsCVE-2026-44200Mediumwagtail: Wagtail has improper permission handling when copying pagesCVE-2026-44201Mediumwagtail: Wagtail has improper restriction handling on Documents and Images APICVE-2026-44199Mediumwagtail: Wagtail has improper permission handling when deleting form submissionsCVE-2026-44198Mediumwagtail: Wagtail has improper permission handling when viewing page historyCVE-2026-44197Mediumwagtail: Wagtail has improper permission handling when comparing revisionsCVE-2026-28223Mediumwagtail: Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interfaceCVE-2026-28222Mediumwagtail: Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributesCVE-2026-25517Mediumwagtail: Wagtail has improper permission handling on admin preview endpointsCVE-2024-39317Highwagtail: Wagtail regular expression denial-of-service via search query parsingCVE-2024-35228Mediumwagtail: Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`CVE-2024-32882Lowwagtail: Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`CVE-2023-45809Lowwagtail: Wagtail vulnerable to disclosure of user names via admin bulk action viewsCVE-2023-28837Mediumwagtail: Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large filesCVE-2023-28836Highwagtail: Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin viewsCVE-2022-21683Mediumwagtail: Comment reply notifications sent to incorrect users

Stop the waste.
Protect your environment with Kodem.