Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form pages they don't have access to by crafting a form submission to delete submissions on a page they do have access to for submissions they don't. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.
References
| Link | Resource |
|---|---|
| https://github.com/wagtail/wagtail/security/advisories/GHSA-pwm3-7fv4-g6xx | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
12 May 2026, 15:58
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/wagtail/wagtail/security/advisories/GHSA-pwm3-7fv4-g6xx - Vendor Advisory | |
| First Time |
Torchbox
Torchbox wagtail |
|
| CPE | cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:* |
11 May 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-11 16:17
Updated : 2026-05-12 15:58
NVD link : CVE-2026-44199
Mitre link : CVE-2026-44199
CVE.ORG link : CVE-2026-44199
JSON object : View
Products Affected
torchbox
- wagtail
CWE
CWE-280
Improper Handling of Insufficient Permissions or Privileges
