Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the page through the revision compare view if they knew the primary key of two revisions. This could potentially result in disclosure of sensitive information. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.
References
| Link | Resource |
|---|---|
| https://github.com/wagtail/wagtail/security/advisories/GHSA-c6wj-9vcj-75pj | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
12 May 2026, 15:58
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:* | |
| First Time |
Torchbox
Torchbox wagtail |
|
| References | () https://github.com/wagtail/wagtail/security/advisories/GHSA-c6wj-9vcj-75pj - Vendor Advisory |
11 May 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-11 16:17
Updated : 2026-05-12 15:58
NVD link : CVE-2026-44197
Mitre link : CVE-2026-44197
CVE.ORG link : CVE-2026-44197
JSON object : View
Products Affected
torchbox
- wagtail
CWE
CWE-280
Improper Handling of Insufficient Permissions or Privileges
