This release includes 5 security fixes for security teams reviewing exposed deployments.
Published 1mo
Productivity & Wikis
✓ No known CVEs patched
This release patches 5 known CVEs
Topics
cms
django
python
wagtail
Affected surfaces
auth
rbac
rce_ssrf
Summary
AI summaryMultiple security fixes including improper restriction, DoS, permission handling, translation bypass, and reflected XSS.
Full changelog
- CVE-2026-54259: Improper restriction handling on Documents and Images chosen endpoints
- CVE-2026-54260: Denial of service via unbounded filter specs in the image preview
- CVE-2026-54261: Improper permission handling in image preview
- CVE-2026-54262: Pages translations can be created without page permissions when using simple_translation
- CVE-2026-54263: Reflected XSS in dynamic image URL generator view
Security Fixes
- CVE-2026-54259 — Improper restriction handling on Documents and Images chosen endpoints
- CVE-2026-54260 — Denial of service via unbounded filter specs in the image preview
- CVE-2026-54261 — Improper permission handling in image preview
- CVE-2026-54262 — Pages translations can be created without page permissions when using simple_translation
- CVE-2026-54263 — Reflected XSS in dynamic image URL generator view
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Wagtail
Django content management system focused on flexibility and user experience.
Related context
Related tools
Beta — feedback welcome: [email protected]