Technology · PyPI
Mezzanine (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 6 vulnerabilities in Mezzanine (PyPI): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-25169, was published on 7 July 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 0
- Exploited in the wild
- 0
About Mezzanine (PyPI)
A content management platform built on the Django framework.
Latest Mezzanine (PyPI) vulnerabilities
- CVE-2024-25169: PYSEC-2026-1627 - Mezzanine allows attackers to bypass access control mechanismsinfoEPSS 1.1%
- CVE-2024-25170: PYSEC-2026-1626 - Mezzanine allows attackers to bypass access controls via manipulating the Host headerinfoCVSS 0EPSS 0.9%
- CVE-2025-50481: Mezzanine CMS stored XSS in blog post componentmediumCVSS 4.8EPSS 0.6%
- CVE-2025-6050: Mezzanine CMS stored XSS in displayable_links_js functionmediumCVSS 4EPSS 0.3%
- CVE-2025-29573: Mezzanine CMS persistent XSS in Forms module via malicious filenamemediumCVSS 6.1EPSS 0.3%
- CVE-2020-19002: PYSEC-2021-343 - Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the…lowCVSS 3.1EPSS 1.1%
Most severe Mezzanine (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-29573: Mezzanine CMS persistent XSS in Forms module via malicious filenamemediumCVSS 6.1EPSS 0.3%
- CVE-2025-50481: Mezzanine CMS stored XSS in blog post componentmediumCVSS 4.8EPSS 0.6%
- CVE-2025-6050: Mezzanine CMS stored XSS in displayable_links_js functionmediumCVSS 4EPSS 0.3%
- CVE-2020-19002: PYSEC-2021-343 - Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the…lowCVSS 3.1EPSS 1.1%
- CVE-2024-25170: PYSEC-2026-1626 - Mezzanine allows attackers to bypass access controls via manipulating the Host headerinfoCVSS 0EPSS 0.9%
- CVE-2024-25169: PYSEC-2026-1627 - Mezzanine allows attackers to bypass access control mechanismsinfoEPSS 1.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/mezzanine.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Mezzanine (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/mezzanine, 26 September 2026.