GHSA-gv5h-5655-h4mvMediumCVSS 5.5

django CMS Cross-Site Scripting (XSS)

Published
November 18, 2024
Last Modified
June 9, 2026

🔗 CVE IDs covered (1)

📋 Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.

🎯 Affected products2

  • pip/django-cms:>= 3.11.7, < 3.11.9
  • pip/django-cms:>= 4.1.2, < 4.1.4

🔗 References (8)