django-cms
PyPI10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting django-cmspage 1 of 1
- CVE-2015-5081HIGHCVSS 8.8EG 8.8fixed in 3.0.14 or 3.1.1, by version range2017-08-18
vulnerable: 2.0.1 ... 2.1.0.rc2 (50 versions)
Cross-site request forgery (CSRF) vulnerability in django CMS before 3.0.14, 3.1.x before 3.1.1 allows remote attackers to manipulate privileged users into performing unknown actions via unspecified vectors.
- CVE-2021-44649MEDIUMCVSS 5.4EG 5.4fixed in 3.7.4, 3.6.1, 3.5.4 or 3.4.7, by version range2022-01-12
vulnerable: 3.4.0 ... 3.7.3 (16 versions)
Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary Jav…
- CVE-2024-11319MEDIUMCVSS 4.8EG 4.8fixed in 3.11.9 or 4.1.4, by version range2024-11-18
vulnerable: 4.1.2, 4.1.3
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS). This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.
- CVE-2026-54622MEDIUMCVSS 6.5EG 6.5fixed in 5.0.82026-08-20
vulnerable: 2.0.1 ... 5.0.7 (140 versions)
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the copy_plugins endpoint in cms/admin/placeholderadmin.py authorizes only the destination clipboard. The _copy_plu…
- CVE-2026-54623HIGHCVSS 7.1EG 7.1fixed in 5.0.82026-08-20
vulnerable: 2.0.1 ... 5.0.7 (140 versions)
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value withou…
- CVE-2026-54624MEDIUMCVSS 6.5EG 6.5fixed in 5.0.82026-08-20
vulnerable: 2.0.1 ... 5.0.7 (140 versions)
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, render_object_structure in cms/views.py renders cms/toolbar/structure.html for a PageContent object without calling…
- CVE-2026-54625MEDIUMCVSS 4.8EG 4.8fixed in 5.0.82026-08-20
vulnerable: 2.0.1 ... 5.0.7 (140 versions)
django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key functio…
- CVE-2026-61663MEDIUMCVSS 4.3EG 4.3fixed in 5.0.92026-08-20
vulnerable: 2.0.1 ... 5.0.8 (141 versions)
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, render_object_structure fails to authorize non-PageContent objects that use PlaceholderRelationField. An active sta…
- CVE-2026-63003MEDIUMCVSS 6.5EG 6.5fixed in 5.0.92026-08-20
vulnerable: 2.0.1 ... 5.0.8 (141 versions)
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on the source page. In cms/admin/forms.py, DuplicatePage…
- CVE-2026-75526MEDIUMCVSS 4.4EG 4.4fixed in 5.0.92026-08-20
vulnerable: 5.0.8
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled values t…
Check whether django-cms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for django-cms CVEs against the assets you own.
Book a Demo →