Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

140 advisories

Loading
Wagtail: Improper restriction handling on Page translation API endpoint Moderate
GHSA-jm5p-837g-rv8g was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman and tinyb0y tinyb0y tinyb0y
Wagtail: Improper permission handling when copying snippets Moderate
GHSA-x5cx-w6p2-mxf2 was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman and tinyb0y tinyb0y tinyb0y
Wagtail: Improper restriction handling on descendant collections in Documents and Images API Moderate
GHSA-c2xx-cjmh-9q8f was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman, RealOrangeOne, and thientd RealOrangeOne RealOrangeOne
thientd thientd
Wagtail: Identification of documents by SHA1 hash Low
GHSA-92hv-j533-69wc was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman, unknownhad, and RealOrangeOne unknownhad unknownhad
RealOrangeOne RealOrangeOne
Wagtail: Improper restriction handling on Pages admin API Moderate
CVE-2026-55468 was published for wagtail (pip) Aug 20, 2026
zerolab Credited to zerolab and thibaudcolas thibaudcolas thibaudcolas
Wagtail: Pages translations can be created without page permissions when using simple_translation Moderate
CVE-2026-54262 was published for wagtail (pip) Aug 20, 2026
devansh3008 Credited to devansh3008, zerolab, gasman, and iaohkut-from-NightWolf-Team zerolab zerolab
gasman gasman iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
Wagtail: Improper permission handling in image preview Moderate
CVE-2026-54261 was published for wagtail (pip) Aug 20, 2026
zerolab Credited to zerolab, 0x1saac, and harshakshit 0x1saac 0x1saac
harshakshit harshakshit
Wagtail: Improper restriction handling on Documents and Images chosen endpoints Moderate
CVE-2026-54259 was published for wagtail (pip) Aug 20, 2026
harshakshit Credited to harshakshit, zerolab, and gasman zerolab zerolab
gasman gasman
Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads Moderate
CVE-2026-32639 was published for winter/wn-cms-module (Composer) Aug 12, 2026
Vincent550102 Credited to Vincent550102
CassianStarck Credited to CassianStarck
Keycloak Vulnerable to Improper Handling of Insufficient Permissions or Privilege Moderate
CVE-2026-9792 was published for org.keycloak:keycloak-services (Maven) May 28, 2026
ProTip! Advisories are also available from the GraphQL API