Technology · Wagtail
Wagtail vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in Wagtail: 0 in the last 7 days and 10 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55468, was published on 24 August 2026.
- Last 7 days
- 0
- Last 90 days
- 10
- Critical, all time
- 0
- Exploited in the wild
- 0
About Wagtail
An open-source Django-based content management system.
Latest Wagtail vulnerabilities
- CVE-2026-55468: Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on…mediumCVSS 4.3EPSS 0.3%
- Wagtail improper permission restriction on page translation APImediumCVSS 6.5
- Wagtail improper permission handling when copying snippetsmediumCVSS 6.5
- Wagtail improper restriction handling in Documents and Images APImediumCVSS 5.3
- Wagtail document SHA1 hash enumeration via HTTP headerslowCVSS 3.7
- CVE-2026-54263: Wagtail reflected XSS in dynamic image URL generatorhighCVSS 7.3EPSS 0.4%
- CVE-2026-54262: Wagtail improper permission handling in simple_translationmediumCVSS 4.3EPSS 0.3%
- CVE-2026-54261: Wagtail improper permission handling in image previewmediumCVSS 6.5EPSS 0.3%
- CVE-2026-54260: Wagtail denial of service via unbounded filter specs in image previewmediumCVSS 4.3EPSS 0.4%
- CVE-2026-54259: Wagtail improper permissions in Documents and Images choosermediumCVSS 4.3EPSS 0.3%
- CVE-2026-44201: Wagtail information disclosure in Documents and Images APImediumCVSS 5.3EPSS 0.3%
- CVE-2026-44200: Wagtail improper permission handling in page copyingmediumCVSS 6.5EPSS 0.3%
- CVE-2026-44199: Wagtail improper permission handling in form submission deletionmediumCVSS 6.5EPSS 0.3%
- CVE-2026-44198: Wagtail improper permission handling in page history reportmediumCVSS 4.3EPSS 0.3%
- CVE-2026-44197: Wagtail improper permission handling in revision compare viewmediumCVSS 6.5EPSS 0.4%
- CVE-2026-28222: Wagtail stored XSS in TableBlock class attributesmediumCVSS 6.1EPSS 0.6%
- CVE-2024-39317: Wagtail ReDoS in parse_query_stringmediumCVSS 6.5EPSS 0.6%
- CVE-2023-28837: PYSEC-2023-56 - Wagtail is an open source content management system built on Django. Prior to versions 4.1.4 and 4.2.2, a…lowCVSS 3.1EPSS 1.1%
- CVE-2021-32681: Wagtail XSS in StreamField include_block tagmediumCVSS 5.4EPSS 1.1%
- CVE-2020-15118: PYSEC-2020-154 - In Wagtail before versions 2.7.4 and 2.9.3, when a form page type is made available to Wagtail editors…lowCVSS 3.1EPSS 1.1%
Most severe Wagtail vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-54263: Wagtail reflected XSS in dynamic image URL generatorhighCVSS 7.3EPSS 0.4%
- CVE-2024-39317: Wagtail ReDoS in parse_query_stringmediumCVSS 6.5EPSS 0.6%
- CVE-2026-44197: Wagtail improper permission handling in revision compare viewmediumCVSS 6.5EPSS 0.4%
- CVE-2026-54261: Wagtail improper permission handling in image previewmediumCVSS 6.5EPSS 0.3%
- CVE-2026-44200: Wagtail improper permission handling in page copyingmediumCVSS 6.5EPSS 0.3%
- CVE-2026-44199: Wagtail improper permission handling in form submission deletionmediumCVSS 6.5EPSS 0.3%
- Wagtail improper permission restriction on page translation APImediumCVSS 6.5
- Wagtail improper permission handling when copying snippetsmediumCVSS 6.5
- CVE-2026-28222: Wagtail stored XSS in TableBlock class attributesmediumCVSS 6.1EPSS 0.6%
- CVE-2021-32681: Wagtail XSS in StreamField include_block tagmediumCVSS 5.4EPSS 1.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 5 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 4 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/wagtail.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Wagtail vulnerabilities", https://junglewise.ai/threats/technologies/wagtail, 26 September 2026.