Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Torchbox

First CVE: Apr 14, 2020Active for: 6 yearsTotal CVEs: 23
19.2
VTI Score
Low

Torchbox maintains Wagtail, a widely deployed open-source content management system that serves as the editorial backbone for many media and publishing platforms. The vendor's vulnerability profile centers on web application attack surface issues—cross-site scripting, privilege escalation, information exposure, resource exhaustion, and race conditions—that reflect the typical exposure of systems managing user input, content workflows, and concurrent access to shared resources. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
5.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Torchbox over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2020
6 years ago
Most Recent CVE
Jul 1, 2026
23 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-54263HIGH
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflected cross-site scripting (XSS) vulnerability exists on the d
Jul 1, 20267.333NONO
CVE-2026-54261MEDIUM
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a
Jul 1, 20266.531NONO
CVE-2026-44200MEDIUM
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have acces
May 11, 20266.527NONO
CVE-2026-44199MEDIUM
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form p
May 11, 20266.527NONO
CVE-2026-44197MEDIUM
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the pag
May 11, 20266.526NONO
CVE-2026-54262MEDIUM
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can
Jul 1, 20264.325NONO
CVE-2026-54259MEDIUM
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly lis
Jul 1, 20264.325NONO
CVE-2026-44201MEDIUM
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A
May 11, 20265.324NONO
CVE-2026-54260LOW
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an authenticated admin user can trigger expensive rendition proces
Jul 1, 20262.722NONO
CVE-2026-28223MEDIUM
Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on c
Mar 5, 20266.122NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
13%
83%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (4.3%)
Network22 (95.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (95.7%)
High1 (4.3%)
Unknown0 (0.0%)
User Interaction
None15 (65.2%)
Unknown0 (0.0%)
Required8 (34.8%)
Privileges Required
Low14 (60.9%)
High8 (34.8%)
None1 (4.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Torchbox.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Torchbox — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Torchbox's Products

View all 1 CNAs →

Top CWEs