Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3824
  • PyPI/django-cms
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) 10 Sep
  • Fix available
  • Severity - 4.8 (Medium)
PYSEC-2026-3822
  • PyPI/django-cms
django CMS: Plugin move endpoint allows cyclic reparenting (DoS) 10 Sep
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-3823
  • PyPI/django-cms
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff 10 Sep
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-3821
  • PyPI/django-cms
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass) 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3825
  • PyPI/django-cms
django CMS: Stored XSS in edit-mode plugin exception rendering 10 Sep
  • Fix available
  • Severity - 4.4 (Medium)
PYSEC-2026-3826
  • PyPI/django-cms
django CMS: Structure endpoint bypasses page-view permission 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3820
  • PyPI/django-cms
django CMS: Clipboard copy IDOR discloses unauthorized plugin content 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-fwjf-m4qw-9f2x
  • PyPI/django-cms
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) 24 Aug
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-8jj7-4v57-frf5
  • PyPI/django-cms
django CMS: Plugin move endpoint allows cyclic reparenting (DoS) 24 Aug
  • Fix available
  • Severity - 7.1 (High)
GHSA-8qj2-c6q4-f399
  • PyPI/django-cms
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff 20 Aug
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-6x92-6vx4-5fwr
  • PyPI/django-cms
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass) 20 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-hvq6-2r72-p2x7
  • PyPI/django-cms
django CMS: Stored XSS in edit-mode plugin exception rendering 20 Aug
  • Fix available
  • Severity - 4.4 (Medium)
GHSA-vgxm-h9gx-h9w7
  • PyPI/django-cms
django CMS: Structure endpoint bypasses page-view permission 20 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-4xfr-4p46-gc6p
  • PyPI/django-cms
django CMS: Clipboard copy IDOR discloses unauthorized plugin content 20 Aug
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3717
  • PyPI/django
See record for full details 04 Aug
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-r3hx-x5rh-p9vv
  • PyPI/django-haystack
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization 15 Jul
  • Fix available
  • Severity - 8.7 (High)