Junglewise Threat Intelligence

CVE-2026-93456: django-page-cms CSRF protection bypass in admin views

CVE-2026-93456 · Severity: high · CVSS 8.2 · Published 2026-09-18

Executive brief

django-page-cms is a content management plugin for Django that allows editors to manage and publish web pages. Five admin mutation views lack CSRF protection, allowing attackers to trick signed-in editors into unknowingly modifying page content through forged requests. This can be exploited to inject unescaped content that renders to all visitors, enabling stored cross-site scripting (XSS) attacks that compromise the website.

Technical details

The vulnerability is a cross-site request forgery (CSRF) protection bypass in five admin mutation views located in pages/admin/views.py. These views are exempted from Django's CSRF middleware protection, allowing unauthenticated attackers to forge POST requests that modify page content when an authenticated editor visits a malicious page. The root cause is the improper use or absence of CSRF token validation decorators on these specific views. An attacker can craft a malicious page containing hidden forms that automatically submit requests to modify content, and if an authenticated editor visits that page, the requests execute with the editor's privileges. The vulnerability enables stored XSS attacks because attackers can inject unescaped content that persists and executes for all site visitors.

Affected products

  • batiste django-page-cms through 2.0.13

Timeline

  • 2026-09-18: disclosed: CVE-2026-93456 published on NVD

References

Related threats