CVE-2026-54623

Source
https://cve.org/CVERecord?id=CVE-2026-54623
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54623.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54623
Aliases
  • GHSA-8jj7-4v57-frf5
Published
2026-08-20T18:02:45.599Z
Modified
2026-08-22T03:58:06.517136557Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
Details

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the moveplugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled pluginparent value without rejecting a plugin’s own identifier or a descendant identifier. A staff user with plugin-change permission under CMSPERMISSION can create a parentid cycle in the plugin tree. The getdescendantscte and getancestorscte queries in cms/models/pluginmodel.py have no cycle guard, so get_descendants() and later rendering, copy, or delete operations can recurse indefinitely or reach a database recursion limit, corrupting the tree and consuming request workers. This issue is fixed in versions 5.0.8.

Database specific
{
    "cwe_ids": [
        "CWE-674",
        "CWE-835"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54623.json"
}
References

Affected packages

Git / github.com/django-cms/django-cms

Affected ranges

Type
GIT
Repo
https://github.com/django-cms/django-cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.0.8"
        }
    ]
}

Affected versions

2.*
2.1.0
2.1.0.rc2
2.1.0.rc3
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.3
2.3.2
2.3.2.rc1
2.3.3
2.3.4
2.3.5
2.3rc1
2.4.0
2.4.0.rc1
2.4.1
3.*
3.0
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.1
3.0.10
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.0c1
3.0c2
3.1
3.2.0
3.2.0.rc1
3.2.0.rc10
3.2.0.rc11
3.2.0.rc12
3.2.0.rc13
3.2.0.rc14
3.2.0.rc3
3.2.0.rc4
3.2.0.rc5
3.2.0.rc6
3.2.0.rc7
3.2.0.rc8
3.2.0.rc9
3.3.0
3.3.0.rc2
3.3.0.rc3
3.3.0.rc4
3.4.0
3.4.0rc1
3.4.0rc2
3.4.0rc3
3.4.1
3.4.2
3.5.0
3.5.0rc1
3.5.1
3.5.2
4.*
4.0.0
4.0.0dev11
5.*
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Other
show
temporary

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54623.json"