Skip to content

Wagtail

v7.3.3 Security

This release includes 5 security fixes for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 5 known CVEs

Topics

cms django python wagtail

Affected surfaces

auth rbac rce_ssrf

Summary

AI summary

Multiple security fixes including improper restriction, DoS, permission handling, translation bypass, and reflected XSS.

Full changelog
  • CVE-2026-54259: Improper restriction handling on Documents and Images chosen endpoints
  • CVE-2026-54260: Denial of service via unbounded filter specs in the image preview
  • CVE-2026-54261: Improper permission handling in image preview
  • CVE-2026-54262: Pages translations can be created without page permissions when using simple_translation
  • CVE-2026-54263: Reflected XSS in dynamic image URL generator view

Security Fixes

  • CVE-2026-54259 — Improper restriction handling on Documents and Images chosen endpoints
  • CVE-2026-54260 — Denial of service via unbounded filter specs in the image preview
  • CVE-2026-54261 — Improper permission handling in image preview
  • CVE-2026-54262 — Pages translations can be created without page permissions when using simple_translation
  • CVE-2026-54263 — Reflected XSS in dynamic image URL generator view

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Wagtail

Get notified when new releases ship.

Sign up free

About Wagtail

Django content management system focused on flexibility and user experience.

All releases →

Related context

Beta — feedback welcome: [email protected]