Labdigital's vulnerability profile centers on its Wagtail 2FA authentication plugin, a niche component for adding two-factor authentication to the Wagtail content-management system. The observed weaknesses cluster around authentication and authorization logic—including authentication bypass through spoofing, improper authorization checks, and gaps in multi-factor authentication workflows—reflecting the critical trust assumptions embedded in access-control mechanisms. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Labdigital over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16766HIGH When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They ca | Nov 29, 2019 | 8.8 | 25 | NO | NO |
CVE-2020-5240HIGH In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permissions | Mar 13, 2020 | 8.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Labdigital.
Media articles that mention a CVE ID that affects a product developed by Labdigital — matched by CVE ID, not by vendor name.