Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on confirmation messages within the wagtail.contrib.simple_translation module. A user with access to the Wagtail admin area may create a page with a specially-crafted title which, when another user performs the "Translate" action, causes arbitrary JavaScript code to run. This could lead to performing actions with that user's credentials. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been patched in versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1.
References
Configurations
Configuration 1 (hide)
|
History
09 Mar 2026, 20:54
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:* cpe:2.3:a:torchbox:wagtail:7.3:rc1:*:*:*:*:*:* cpe:2.3:a:torchbox:wagtail:7.3:-:*:*:*:*:*:* |
|
| References | () https://github.com/wagtail/wagtail/commit/1c6f2effed68f4ccad6fbd07987e03641505f863 - Patch | |
| References | () https://github.com/wagtail/wagtail/commit/ba70244d376a7b1bd180ded03e827917ff410c19 - Patch | |
| References | () https://github.com/wagtail/wagtail/commit/d8c5900982df8ed5938ad993aa9ff69cda50f80c - Patch | |
| References | () https://github.com/wagtail/wagtail/commit/ee39d39deeb7f250fe886417b24802d7e05b1143 - Patch | |
| References | () https://github.com/wagtail/wagtail/releases/tag/v6.3.8 - Product, Release Notes | |
| References | () https://github.com/wagtail/wagtail/releases/tag/v7.0.6 - Product, Release Notes | |
| References | () https://github.com/wagtail/wagtail/releases/tag/v7.2.3 - Product, Release Notes | |
| References | () https://github.com/wagtail/wagtail/releases/tag/v7.3.1 - Product, Release Notes | |
| References | () https://github.com/wagtail/wagtail/security/advisories/GHSA-p4v8-rw59-93cq - Vendor Advisory | |
| First Time |
Torchbox
Torchbox wagtail |
09 Mar 2026, 13:36
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
05 Mar 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-05 20:16
Updated : 2026-03-09 20:54
NVD link : CVE-2026-28223
Mitre link : CVE-2026-28223
CVE.ORG link : CVE-2026-28223
JSON object : View
Products Affected
torchbox
- wagtail
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
