piccolo-admin
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting piccolo-adminpage 1 of 1
- CVE-2024-30248HIGHCVSS 7.7EG 7.7✓ Fixed in 1.3.22024-04-02
vulnerable: 1.2.0, 1.2.1, 1.2.2, 1.3.0, 1.3.1
Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel allows media files to be uploaded. As a default, SVG is an allowed file type for upload. An attacker can upload an SVG…
- CVE-2026-55485HIGHCVSS 8.8EG 8.8✓ Fixed in 1.14.02026-08-28
vulnerable: 0.1.0 ... 1.9.1 (152 versions)
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers b…
Check whether piccolo-admin is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for piccolo-admin CVEs against the assets you own.
Book a Demo →