CVE-2026-28223Medium· 6.1▾ SunlitWagtail Vulnerable to Cross-site Scripting in simple_translation admin interface
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
A stored Cross-site Scripting (XSS) vulnerability exists on confirmation messages within the wagtail.contrib.simple_translation module. A user with access to the Wagtail admin area may create a page with a specially-crafted title which, when another user performs the "Translate" action, causes arbitrary JavaScript code to run. This could lead to performing actions with that user's credentials. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.
Patched versions have been released as Wagtail 6.3.8, 7.0.6, 7.2.3 and 7.3.1.
None
Many thanks to Guan Chenxian (@GCXWLP) for reporting this issue.
If there are any questions or comments about this advisory:
wagtail < 6.3.8wagtail >= 6.4rc1, < 7.0.6wagtail >= 7.1rc1, < 7.2.3wagtail >= 7.3rc1, < 7.3.1Upgrade to a patched release:
wagtail 6.3.8wagtail 7.0.6wagtail 7.2.3wagtail 7.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-28222Medium· 6.1Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes
CVE-2021-29434Medium· 6.1Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields
CVE-2023-28836Medium· 6.4Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views
CVE-2023-28837Medium· 4.4Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files
CVE-2020-15118Medium· 5.7Cross-Site Scripting in Wagtail
CVE-2026-55468Medium· 4.3Wagtail: Improper restriction handling on Pages admin API