VulnSea

django-cms vulnerabilities

CVEs whose affected-version data names the django-cms package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-54623High· 7.1
1mo ago

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value with…

Twilightdjango-cms · django-cmsEPSS 0.34%via NVD
CVE-2026-54625Medium· 4.8
1mo ago

django CMS is a content management system powered by Django

django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key funct…

Sunlitdjango-cms · django-cmsEPSS 0.15%via NVD
CVE-2026-54622Medium· 6.5
1mo ago

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

Sunlitdjango-cms · django-cmsEPSS 0.24%via OSV
CVE-2026-54624Medium· 6.5
1mo ago

django CMS: Structure endpoint bypasses page-view permission

django CMS: Structure endpoint bypasses page-view permission

Sunlitdjango-cms · django-cmsEPSS 0.24%via OSV
CVE-2026-75526Medium· 4.4
1mo ago

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled values…

Sunlitdjango-cms · django-cmsEPSS 0.17%via NVD
CVE-2026-63003Medium· 6.5
1mo ago

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on the source page. In cms/admin/forms.py, DuplicatePa…

Sunlitdjango-cms · django-cmsEPSS 0.24%via NVD
CVE-2026-61663Medium· 4.3
1mo ago

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

Sunlitdjango-cms · django-cmsEPSS 0.25%via OSV
django-cms vulnerabilities (CVEs) · VulnSea