Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3939
  • PyPI/wagtail
Wagtail: Improper restriction handling on Pages admin API 10 Sep
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-jm5p-837g-rv8g
  • PyPI/wagtail
Wagtail: Improper restriction handling on Page translation API endpoint 20 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-x5cx-w6p2-mxf2
  • PyPI/wagtail
Wagtail: Improper permission handling when copying snippets 20 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-c2xx-cjmh-9q8f
  • PyPI/wagtail
Wagtail: Improper restriction handling on descendant collections in Documents and Images API 20 Aug
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-92hv-j533-69wc
  • PyPI/wagtail
Wagtail: Identification of documents by SHA1 hash 20 Aug
  • Fix available
  • Severity - 3.7 (Low)
GHSA-3vrh-m9w7-v94f
  • PyPI/wagtail
Wagtail: Improper restriction handling on Pages admin API 20 Aug
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-23m2-mghx-vqmf
  • PyPI/wagtail
Wagtail: Reflected XSS in dynamic image URL generator view 20 Aug
  • Fix available
  • Severity - 7.3 (High)
GHSA-8634-mr4j-r72c
  • PyPI/wagtail
Wagtail: Pages translations can be created without page permissions when using simple_translation 20 Aug
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-r6p4-grq7-xm4m
  • PyPI/wagtail
Wagtail: Improper permission handling in image preview 20 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-f2p5-j6fg-5cxf
  • PyPI/wagtail
Wagtail: Denial of service via unbounded filter specs in the image preview 20 Aug
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-h54r-xq46-qwqm
  • PyPI/wagtail
Wagtail: Improper restriction handling on Documents and Images chosen endpoints 20 Aug
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-2030
  • PyPI/wagtail
Wagtail has improper permission handling on admin preview endpoints 07 Jul
  • Fix available
  • Severity - 5.1 (Medium)
PYSEC-2026-2032
  • PyPI/wagtail
Improper Handling of Insufficient Permissions in `wagtail.contrib.settings` 07 Jul
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-2031
  • PyPI/wagtail
Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet` 07 Jul
  • Fix available
  • Severity - 2.7 (Low)
PYSEC-2026-616
  • PyPI/wagtail
See record for full details 01 Jul
  • Fix available
  • Severity - 7.3 (High)
PYSEC-2026-615
  • PyPI/wagtail
See record for full details 01 Jul
  • Fix available
  • Severity - 4.3 (Medium)