Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Thibaudcolas

#40254of 56,330
7.3Total CVSS
Vulnerabilities · 1
PT-2026-54840
7.3
2026-07-01
Wagtail · Wagtail · CVE-2026-54263
**Name of the Vulnerable Software and Affected Versions** Wagtail versions prior to 7.0.8 Wagtail versions prior to 7.3.3 Wagtail versions prior to 7.4.2 **Description** A reflected cross-site scripting (XSS) issue exists in the dynamic image URL generator view within the admin interface. An attacker with limited-permission editor credentials can craft a malicious URL that, if accessed by a user with higher privileges, allows the execution of actions using those elevated credentials. This issue affects all sites regardless of whether the dynamic image serve view is enabled and cannot be exploited by visitors who lack admin access. **Recommendations** Update to version 7.0.8. Update to version 7.3.3. Update to version 7.4.2.