Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3824
  • PyPI/django-cms
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) 10 Sep
  • Fix available
  • Severity - 4.8 (Medium)
PYSEC-2026-3822
  • PyPI/django-cms
django CMS: Plugin move endpoint allows cyclic reparenting (DoS) 10 Sep
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-3823
  • PyPI/django-cms
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff 10 Sep
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-3821
  • PyPI/django-cms
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass) 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3825
  • PyPI/django-cms
django CMS: Stored XSS in edit-mode plugin exception rendering 10 Sep
  • Fix available
  • Severity - 4.4 (Medium)
PYSEC-2026-3826
  • PyPI/django-cms
django CMS: Structure endpoint bypasses page-view permission 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3820
  • PyPI/django-cms
django CMS: Clipboard copy IDOR discloses unauthorized plugin content 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-fwjf-m4qw-9f2x
  • PyPI/django-cms
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) 24 Aug
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-8jj7-4v57-frf5
  • PyPI/django-cms
django CMS: Plugin move endpoint allows cyclic reparenting (DoS) 24 Aug
  • Fix available
  • Severity - 7.1 (High)
GHSA-8qj2-c6q4-f399
  • PyPI/django-cms
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff 20 Aug
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-6x92-6vx4-5fwr
  • PyPI/django-cms
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass) 20 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-hvq6-2r72-p2x7
  • PyPI/django-cms
django CMS: Stored XSS in edit-mode plugin exception rendering 20 Aug
  • Fix available
  • Severity - 4.4 (Medium)
GHSA-vgxm-h9gx-h9w7
  • PyPI/django-cms
django CMS: Structure endpoint bypasses page-view permission 20 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-4xfr-4p46-gc6p
  • PyPI/django-cms
django CMS: Clipboard copy IDOR discloses unauthorized plugin content 20 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-gv5h-5655-h4mv
  • PyPI/django-cms
django CMS Cross-Site Scripting (XSS) 18 Nov 2024
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-2pqc-gv8q-pvqv
  • PyPI/django-cms
django-cms CSRF Vulnerability 17 May 2022
  • Fix available
  • Severity - 8.7 (High)