PT-2026-95218 · Pypi · Django-Page-Cms

·

CVE-2026-93456

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions django-page-cms versions prior to 2.0.14
Description Five admin mutation views in pages/admin/views.py are exempt from Cross-Site Request Forgery (CSRF) protection. This allows attackers to forge requests that modify page content. Signed-in editors who visit a malicious page can be tricked into storing unescaped content that renders to all visitors, leading to stored cross-site scripting (XSS) attacks.
Recommendations Update django-page-cms to version 2.0.14 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93456

Affected Products

Django-Page-Cms