Wagtail
Vendor:
First CVE: Apr 14, 2020 · Active for 6 years
23
Total CVEs
More Total CVEs than 95% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wagtail over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2020
6 years ago
Most Recent CVE
Jul 1, 2026
24 days ago
CVE Severity & Scoring
Wagtail23 CVEs
13%
83%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (4.3%)
Network22 (95.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (95.7%)
High1 (4.3%)
Unknown0 (0.0%)
User Interaction
None15 (65.2%)
Unknown0 (0.0%)
Required8 (34.8%)
Privileges Required
Low14 (60.9%)
High8 (34.8%)
None1 (4.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54263HIGH Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflected cross-site scripting (XSS) vulnerability exists on the d | Jul 1, 2026 | 7.3 | 33 | NO | NO |
CVE-2026-54261MEDIUM Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a | Jul 1, 2026 | 6.5 | 31 | NO | NO |
CVE-2026-44200MEDIUM Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have acces | May 11, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-44199MEDIUM Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form p | May 11, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-44197MEDIUM Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the pag | May 11, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-54262MEDIUM Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can | Jul 1, 2026 | 4.3 | 25 | NO | NO |
CVE-2026-54259MEDIUM Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly lis | Jul 1, 2026 | 4.3 | 25 | NO | NO |
CVE-2026-44201MEDIUM Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A | May 11, 2026 | 5.3 | 24 | NO | NO |
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an authenticated admin user can trigger expensive rendition proces | Jul 1, 2026 | 2.7 | 22 | NO | NO |
CVE-2026-28223MEDIUM Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on c | Mar 5, 2026 | 6.1 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Wagtail
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.3 | 2 | 6.1 | 0.4% | 0 | 0 |
| 2.8 | 1 | 6.8 | 1.3% | 0 | 0 |