Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.1
Wagtail Admin Panel Allows Malicious JavaScript to Run
CVE-2026-28223
GHSA-p4v8-rw59-93cq
Summary
A vulnerability in Wagtail's admin panel allows an attacker with admin access to inject malicious JavaScript code. This could be used to steal a legitimate user's credentials or take other malicious actions. To fix this, update Wagtail to version 6.3.8, 7.0.6, 7.2.3, or 7.3.1 or later.
What to do
- Update wagtail to version 6.3.8.
- Update wagtail to version 7.0.6.
- Update wagtail to version 7.2.3.
- Update wagtail to version 7.3.1.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| – | wagtail | <= 6.3.8 | 6.3.8 |
| – | wagtail | > 6.4rc1 , <= 7.0.6 | 7.0.6 |
| – | wagtail | > 7.1rc1 , <= 7.2.3 | 7.2.3 |
| – | wagtail | > 7.3rc1 , <= 7.3.1 | 7.3.1 |
| torchbox | wagtail | <= 6.3.8 | – |
| torchbox | wagtail | > 6.4 , <= 7.0.6 | – |
| torchbox | wagtail | > 7.1 , <= 7.2.3 | – |
| torchbox | wagtail | 7.3 | – |
| torchbox | wagtail | 7.3 | – |
Original title
Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on confirmation messa...
Original description
Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on confirmation messages within the wagtail.contrib.simple_translation module. A user with access to the Wagtail admin area may create a page with a specially-crafted title which, when another user performs the "Translate" action, causes arbitrary JavaScript code to run. This could lead to performing actions with that user's credentials. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been patched in versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1.
nvd CVSS3.1
6.1
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
- https://github.com/wagtail/wagtail/commit/1c6f2effed68f4ccad6fbd07987e03641505f8...
- https://github.com/wagtail/wagtail/commit/ba70244d376a7b1bd180ded03e827917ff410c...
- https://github.com/wagtail/wagtail/commit/d8c5900982df8ed5938ad993aa9ff69cda50f8...
- https://github.com/wagtail/wagtail/commit/ee39d39deeb7f250fe886417b24802d7e05b11...
- https://github.com/wagtail/wagtail/releases/tag/v6.3.8
- https://github.com/wagtail/wagtail/releases/tag/v7.0.6
- https://github.com/wagtail/wagtail/releases/tag/v7.2.3
- https://github.com/wagtail/wagtail/releases/tag/v7.3.1
- https://github.com/wagtail/wagtail/security/advisories/GHSA-p4v8-rw59-93cq
- https://nvd.nist.gov/vuln/detail/CVE-2026-28223
- https://github.com/advisories/GHSA-p4v8-rw59-93cq
Published: 5 Mar 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026