---
id: CVE-2026-88420
title: >-
  A reflected cross-site scripting (XSS) vulnerability in the
  EntryAbstract.save() component of APSL puput v1.2.1 through v2.2.0 allows
  authenticated attackers with Wagtail Editor privileges to execute arbitrary
  code in the context of the …
summary: >-
  A reflected cross-site scripting (XSS) vulnerability in the
  EntryAbstract.save() component of APSL puput v1.2.1 through v2.2.0 allows
  authenticated attackers with Wagtail Editor privileges to execute arbitrary
  code in the context of the …
severity: none
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T13:17:16.787'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88420'
references:
  - url: 'https://gist.github.com/itsmohitnarayan/89de718efb225e840719478ed949bd51'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T13:08:53.485Z'
---

## Overview

A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.save() component of APSL puput v1.2.1 through v2.2.0 allows authenticated attackers with Wagtail Editor privileges to execute arbitrary code in the context of the victim's browser via a crafted payload.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
