Technology · PyPI
wagtail (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 26 vulnerabilities in wagtail (PyPI): 0 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55468, was published on 24 August 2026.
- Last 7 days
- 0
- Last 90 days
- 9
- Critical, all time
- 0
- Exploited in the wild
- 0
About wagtail (PyPI)
Django-based open-source content management system with page editing, site administration, and publishing.
Latest wagtail (PyPI) vulnerabilities
- CVE-2026-55468: Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on…mediumCVSS 4.3EPSS 0.3%
- CVE-2026-25517: PYSEC-2026-2030 - Wagtail has improper permission handling on admin preview endpointsmediumCVSS 4EPSS 0.4%
- CVE-2024-35228: PYSEC-2026-2032 - Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`lowCVSS 3.1EPSS 0.3%
- CVE-2024-32882: PYSEC-2026-2031 - Wagtail has permission check bypass when editing a model with per-field restrictions through…lowCVSS 3.1EPSS 0.5%
- CVE-2026-54263: Wagtail reflected XSS in dynamic image URL generatorhighCVSS 7.3EPSS 0.4%
- CVE-2026-54262: Wagtail improper permission handling in simple_translationmediumCVSS 4.3EPSS 0.3%
- CVE-2026-54261: Wagtail improper permission handling in image previewmediumCVSS 6.5EPSS 0.3%
- CVE-2026-54260: Wagtail denial of service via unbounded filter specs in image previewmediumCVSS 4.3EPSS 0.4%
- CVE-2026-54259: Wagtail improper permissions in Documents and Images choosermediumCVSS 4.3EPSS 0.3%
- CVE-2026-44201: Wagtail information disclosure in Documents and Images APImediumCVSS 5.3EPSS 0.3%
- CVE-2026-44200: Wagtail improper permission handling in page copyingmediumCVSS 6.5EPSS 0.3%
- CVE-2026-44199: Wagtail improper permission handling in form submission deletionmediumCVSS 6.5EPSS 0.3%
- CVE-2026-44198: Wagtail improper permission handling in page history reportmediumCVSS 4.3EPSS 0.3%
- CVE-2026-44197: Wagtail improper permission handling in revision compare viewmediumCVSS 6.5EPSS 0.4%
- CVE-2026-28223: PYSEC-2026-2308 - Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6…lowCVSS 3.1EPSS 0.6%
- CVE-2026-28222: Wagtail stored XSS in TableBlock class attributesmediumCVSS 6.1EPSS 0.6%
- CVE-2024-39317: Wagtail ReDoS in parse_query_stringmediumCVSS 6.5EPSS 0.6%
- CVE-2023-45809: PYSEC-2023-219 - Wagtail is an open source content management system built on Django. A user with a limited-permission…lowCVSS 3.1EPSS 0.4%
- CVE-2023-28836: PYSEC-2023-55 - Wagtail is an open source content management system built on Django. Starting in version 1.5 and prior to…lowCVSS 3.1EPSS 0.8%
- CVE-2023-28837: PYSEC-2023-56 - Wagtail is an open source content management system built on Django. Prior to versions 4.1.4 and 4.2.2, a…lowCVSS 3.1EPSS 1.1%
- CVE-2022-21683: PYSEC-2022-13 - Wagtail is a Django based content management system focused on flexibility and user experience. When…lowCVSS 3.1EPSS 1.0%
- CVE-2021-32681: Wagtail XSS in StreamField include_block tagmediumCVSS 5.4EPSS 1.1%
- CVE-2021-29434: PYSEC-2021-114 - Wagtail is a Django content management system. In affected versions of Wagtail, when saving the contents…lowCVSS 3.1EPSS 0.6%
- CVE-2020-15118: PYSEC-2020-154 - In Wagtail before versions 2.7.4 and 2.9.3, when a form page type is made available to Wagtail editors…lowCVSS 3.1EPSS 1.1%
- CVE-2020-11037: PYSEC-2020-153 - In Wagtail before versions 2.7.2 and 2.8.2, a potential timing attack exists on pages or documents that…lowCVSS 3.1EPSS 0.3%
Most severe wagtail (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-54263: Wagtail reflected XSS in dynamic image URL generatorhighCVSS 7.3EPSS 0.4%
- CVE-2024-39317: Wagtail ReDoS in parse_query_stringmediumCVSS 6.5EPSS 0.6%
- CVE-2026-44197: Wagtail improper permission handling in revision compare viewmediumCVSS 6.5EPSS 0.4%
- CVE-2026-54261: Wagtail improper permission handling in image previewmediumCVSS 6.5EPSS 0.3%
- CVE-2026-44200: Wagtail improper permission handling in page copyingmediumCVSS 6.5EPSS 0.3%
- CVE-2026-44199: Wagtail improper permission handling in form submission deletionmediumCVSS 6.5EPSS 0.3%
- CVE-2026-28222: Wagtail stored XSS in TableBlock class attributesmediumCVSS 6.1EPSS 0.6%
- CVE-2021-32681: Wagtail XSS in StreamField include_block tagmediumCVSS 5.4EPSS 1.1%
- CVE-2026-44201: Wagtail information disclosure in Documents and Images APImediumCVSS 5.3EPSS 0.3%
- CVE-2026-54260: Wagtail denial of service via unbounded filter specs in image previewmediumCVSS 4.3EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 3 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pypi-wagtail.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "wagtail (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pypi-wagtail, 28 September 2026.