Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2185709
AlmaLinux
5861
Alpaquita
15521
Alpine
4589
Android
3674
Azure Linux
17153
BellSoft Hardened Containers
744
Bitnami
9225
Chainguard
1020158
CleanStart
3450
CRAN
14
crates.io
2720
Debian
67380
Echo
6546
GHC
3
GIT
106460
GitHub Actions
55
Go
9157
Hackage
32
Hex
351
Julia
1713
Linux
29368
Mageia
6203
Maven
6998
MinimOS
142939
npm
228510
NuGet
1860
opam
29
openEuler
8674
openSUSE
14332
OSS-Fuzz
4004
Packagist
7036
Pub
11
PyPI
25079
Red Hat
23183
Rocky Linux
4234
Root
19469
RubyGems
4709
SUSE
23047
SwiftURL
59
TuxCare
9237
Ubuntu
64508
VSCode
21
Wolfi
287393
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3824
PyPI/django-cms
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
10 Sep
Fix available
Severity - 4.8 (Medium)
PYSEC-2026-3822
PyPI/django-cms
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
10 Sep
Fix available
Severity - 7.1 (High)
PYSEC-2026-3823
PyPI/django-cms
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
10 Sep
Fix available
Severity - 4.3 (Medium)
PYSEC-2026-3821
PyPI/django-cms
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
10 Sep
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-3825
PyPI/django-cms
django CMS: Stored XSS in edit-mode plugin exception rendering
10 Sep
Fix available
Severity - 4.4 (Medium)
PYSEC-2026-3826
PyPI/django-cms
django CMS: Structure endpoint bypasses page-view permission
10 Sep
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-3820
PyPI/django-cms
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
10 Sep
Fix available
Severity - 6.5 (Medium)
GHSA-fwjf-m4qw-9f2x
PyPI/django-cms
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
24 Aug
Fix available
Severity - 4.8 (Medium)
GHSA-8jj7-4v57-frf5
PyPI/django-cms
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
24 Aug
Fix available
Severity - 7.1 (High)
GHSA-8qj2-c6q4-f399
PyPI/django-cms
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
20 Aug
Fix available
Severity - 4.3 (Medium)
GHSA-6x92-6vx4-5fwr
PyPI/django-cms
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
20 Aug
Fix available
Severity - 6.5 (Medium)
GHSA-hvq6-2r72-p2x7
PyPI/django-cms
django CMS: Stored XSS in edit-mode plugin exception rendering
20 Aug
Fix available
Severity - 4.4 (Medium)
GHSA-vgxm-h9gx-h9w7
PyPI/django-cms
django CMS: Structure endpoint bypasses page-view permission
20 Aug
Fix available
Severity - 6.5 (Medium)
GHSA-4xfr-4p46-gc6p
PyPI/django-cms
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
20 Aug
Fix available
Severity - 6.5 (Medium)
GHSA-gv5h-5655-h4mv
PyPI/django-cms
django CMS Cross-Site Scripting (XSS)
18 Nov 2024
Fix available
Severity - 5.1 (Medium)
GHSA-2pqc-gv8q-pvqv
PyPI/django-cms
django-cms CSRF Vulnerability
17 May 2022
Fix available
Severity - 8.7 (High)
Load more...
PyPI - OSV