GHSA-5j3h-q5f7-g2vqHighCVSS 8.2

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages...

Published
September 18, 2026
Last Modified
September 18, 2026

🔗 CVE IDs covered (1)

📋 Description

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing unescaped content that renders to all visitors, enabling stored cross-site scripting attacks.

🔗 References (7)