Torchbox maintains Wagtail, a widely deployed open-source content management system that serves as the editorial backbone for many media and publishing platforms. The vendor's vulnerability profile centers on web application attack surface issues—cross-site scripting, privilege escalation, information exposure, resource exhaustion, and race conditions—that reflect the typical exposure of systems managing user input, content workflows, and concurrent access to shared resources. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Torchbox over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54263HIGH Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflected cross-site scripting (XSS) vulnerability exists on the d | Jul 1, 2026 | 7.3 | 33 | NO | NO |
CVE-2026-54261MEDIUM Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a | Jul 1, 2026 | 6.5 | 31 | NO | NO |
CVE-2026-44200MEDIUM Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have acces | May 11, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-44199MEDIUM Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form p | May 11, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-44197MEDIUM Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the pag | May 11, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-54262MEDIUM Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can | Jul 1, 2026 | 4.3 | 25 | NO | NO |
CVE-2026-54259MEDIUM Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly lis | Jul 1, 2026 | 4.3 | 25 | NO | NO |
CVE-2026-44201MEDIUM Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A | May 11, 2026 | 5.3 | 24 | NO | NO |
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an authenticated admin user can trigger expensive rendition proces | Jul 1, 2026 | 2.7 | 22 | NO | NO |
CVE-2026-28223MEDIUM Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on c | Mar 5, 2026 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Torchbox.
Media articles that mention a CVE ID that affects a product developed by Torchbox — matched by CVE ID, not by vendor name.