Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

11 advisories

Loading
Wagtail: Improper restriction handling on Page translation API endpoint Moderate
GHSA-jm5p-837g-rv8g was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman and tinyb0y tinyb0y tinyb0y
Wagtail: Improper permission handling when copying snippets Moderate
GHSA-x5cx-w6p2-mxf2 was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman and tinyb0y tinyb0y tinyb0y
Wagtail: Improper restriction handling on descendant collections in Documents and Images API Moderate
GHSA-c2xx-cjmh-9q8f was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman, RealOrangeOne, and thientd RealOrangeOne RealOrangeOne
thientd thientd
Wagtail: Identification of documents by SHA1 hash Low
GHSA-92hv-j533-69wc was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman, unknownhad, and RealOrangeOne unknownhad unknownhad
RealOrangeOne RealOrangeOne
Wagtail: Pages translations can be created without page permissions when using simple_translation Moderate
CVE-2026-54262 was published for wagtail (pip) Aug 20, 2026
devansh3008 Credited to devansh3008, zerolab, gasman, and iaohkut-from-NightWolf-Team zerolab zerolab
gasman gasman iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
Wagtail: Improper restriction handling on Documents and Images chosen endpoints Moderate
CVE-2026-54259 was published for wagtail (pip) Aug 20, 2026
harshakshit Credited to harshakshit, zerolab, and gasman zerolab zerolab
gasman gasman
Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interface Moderate
CVE-2026-28223 was published for wagtail (pip) Mar 3, 2026
GCXWLP Credited to GCXWLP, RealOrangeOne, and gasman RealOrangeOne RealOrangeOne
gasman gasman
Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes Moderate
CVE-2026-28222 was published for wagtail (pip) Mar 3, 2026
GCXWLP Credited to GCXWLP, RealOrangeOne, and gasman RealOrangeOne RealOrangeOne
gasman gasman
Wagtail has improper permission handling on admin preview endpoints Moderate
CVE-2026-25517 was published for wagtail (pip) Feb 3, 2026
thxtech Credited to thxtech, gasman, RealOrangeOne, and laymonage gasman gasman
RealOrangeOne RealOrangeOne laymonage laymonage
Improper Handling of Insufficient Permissions in `wagtail.contrib.settings` Moderate
CVE-2024-35228 was published for wagtail (pip) Jun 2, 2024
engineervix Credited to engineervix, gasman, and RealOrangeOne gasman gasman
RealOrangeOne RealOrangeOne
Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields High
CVE-2021-29434 was published for wagtail (pip) Apr 20, 2021
kevthehermit Credited to kevthehermit, gasman, and tdunlap607 gasman gasman
tdunlap607 tdunlap607
ProTip! Advisories are also available from the GraphQL API