Количество 2
Количество 2
CVE-2026-55468
Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.
GHSA-3vrh-m9w7-v94f
Wagtail: Improper restriction handling on Pages admin API
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55468 Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2. | CVSS3: 4.3 | 0% Низкий | 23 дня назад | |
GHSA-3vrh-m9w7-v94f Wagtail: Improper restriction handling on Pages admin API | CVSS3: 4.3 | 0% Низкий | 27 дней назад |
Уязвимостей на страницу