Export limit exceeded: 395546 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395546 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-93455 | 1 Batiste | 1 Django-page-cms | 2026-09-18 | 6.5 Medium |
| django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. Attackers with low-privilege staff credentials can enumerate content identifiers and access unpublished drafts, page listings, and file paths without proper authorization checks. | ||||
| CVE-2026-93456 | 1 Batiste | 1 Django-page-cms | 2026-09-18 | 8.2 High |
| django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing unescaped content that renders to all visitors, enabling stored cross-site scripting attacks. | ||||
Page 1 of 1.