django-cms
The easy-to-use and developer-friendly enterprise CMS powered by Django
Activity
- Latest release
- 2w ago
- Total releases
- 149
- Cadence
- ~20 days
- Last 12 months
- 15
Reach
- Stars
- 10.7k
Details
- License
- BSD-3-Clause
- First release
- Apr 11, 2014
| Version | Released | |
|---|---|---|
5.0.11
patch
| ||
5.1.2
patch
| ||
5.1.1
patch
| ||
5.0.10
patch
| ||
5.1.0
minor
| ||
5.0.9
patch
| ||
5.0.8
patch
3 CVEs
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-75526
PYSEC-2026-3825
GHSA-hvq6-2r72-p2x7
Sep 10, 2026
django CMS: Stored XSS in edit-mode plugin exception rendering
4.4
/ 10
Medium
Network
High
Low
Required
Changed
Low
Low
None
SummaryWhen plugin rendering fails in edit mode, django CMS renders a If an editor could store HTML in data used by a plugin's ImpactThe vulnerable path is only reached when placeholder rendering catches a plugin rendering exception:
In the vulnerable implementation, that message was embedded directly into an HTML heading. The final placeholder content was later returned through
PatchEscape the custom exception heading before returning it as safe placeholder markup. The current fixed code uses
The traceback HTML from WorkaroundsUntil patched, reduce exposure by ensuring only fully trusted staff can edit plugins whose stored fields are included in References
Affected versions
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.7
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.11
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.11.11
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.10
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.6
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.0a1
pre
| ||
5.0.5
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.4
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.9
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.0.dev1
pre
| ||
5.0.3
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.2
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.7
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.1
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.0
major
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.6
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.11.10
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.5
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.0a1
pre
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.4
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.11.9
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.3
patch
7 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-11319
GHSA-gv5h-5655-h4mv
Nov 18, 2024
django CMS Cross-Site Scripting (XSS)
Medium
Network
Low
High
None
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3. Affected versions
3.11.7
3.11.8
4.1.2
4.1.3
Fixed in
3.11.9
4.1.4
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.11.8
patch
7 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-11319
GHSA-gv5h-5655-h4mv
Nov 18, 2024
django CMS Cross-Site Scripting (XSS)
Medium
Network
Low
High
None
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3. Affected versions
3.11.7
3.11.8
4.1.2
4.1.3
Fixed in
3.11.9
4.1.4
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.11.7
patch
7 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-11319
GHSA-gv5h-5655-h4mv
Nov 18, 2024
django CMS Cross-Site Scripting (XSS)
Medium
Network
Low
High
None
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3. Affected versions
3.11.7
3.11.8
4.1.2
4.1.3
Fixed in
3.11.9
4.1.4
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
4.1.2
patch
7 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-11319
GHSA-gv5h-5655-h4mv
Nov 18, 2024
django CMS Cross-Site Scripting (XSS)
Medium
Network
Low
High
None
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3. Affected versions
3.11.7
3.11.8
4.1.2
4.1.3
Fixed in
3.11.9
4.1.4
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.11.6
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.1
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.11.5
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.0
major
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.0rc5
pre
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.11.4
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.0rc4
pre
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.8.2
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.8.1
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.0rc3
pre
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.0rc2
pre
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.11.3
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.11.2
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.0rc1
pre
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.11.1
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.11.1rc1
pre
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.11.0
minor
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.10.1
patch
6 CVEs
CVE-2026-54625
PYSEC-2026-3824
GHSA-fwjf-m4qw-9f2x
Sep 10, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
SummaryThe CMS page cache key ignores the request headers that plugins declare via Details
Impact
Applies only when PatchesFixed in 5.0.8: the page cache now folds the request's values implements PatchesFixed in 5.0.8: the page cache now folds the request's values for plugin-declared vary headers into the content key. The set of vary headers is persisted on write and looked up first on read (mirroring Django's WorkaroundsDisable CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54623
PYSEC-2026-3822
GHSA-8jj7-4v57-frf5
Sep 10, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
SummaryThe Details
Descendant and ancestor traversal is implemented with ImpactAn authenticated staff user with permission to change plugins in at least one placeholder can corrupt that placeholder's plugin tree, causing requests that traverse it (rendering, copy, delete) to hang and consume application workers (denial of service). The tree is also left in a corrupted state. Requires PatchesFixed in 5.0.8: WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-61663
PYSEC-2026-3823
GHSA-8qj2-c6q4-f399
Sep 10, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe django-cms frontend-editing structure endpoint
did not perform an object-level authorization check for non-
SeverityThe issue is staff-gated and read-only, disclosing CMS structure metadata (placeholder slot names, plugin tree, plugin identifiers/labels, object existence) rather than write access or arbitrary field data. Affected versions
Patched versions
Preconditions
ImpactA low-privileged staff user can read the editorial placeholder/plugin structure of non- Proof of conceptUsing django-cms' own test model
Patch
WorkaroundsNo configuration workaround. Deployments that do not register any non- CreditReported by doanmanhducz. Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-63003
PYSEC-2026-3821
GHSA-6x92-6vx4-5fwr
Sep 10, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
ImpactThe only authorization gate on the duplicate flow is
This crosses a real privilege boundary: a staff user restricted (via Read-back is trivial (verified): the copy is created on the attacker’s site and, because
Proof of concept
PatchesEnforce an object-level permission check on
( WorkaroundsUntil patched, restrict access to the References
Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 129 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54624
PYSEC-2026-3826
GHSA-vgxm-h9gx-h9w7
Sep 10, 2026
django CMS: Structure endpoint bypasses page-view permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe structure-board endpoint ( Details
The rendered structure board includes each plugin's ImpactA staff user (any account with This only applies when PatchesFixed in 5.0.8: the structure endpoint now enforces WorkaroundsNone other than restricting staff access. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54622
PYSEC-2026-3820
GHSA-4xfr-4p46-gc6p
Sep 10, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryThe clipboard copy paths of the DetailsIn ImpactA staff user holding the global add permission for a plugin type, but with no access to a given placeholder/page, can copy that placeholder's plugins into their own clipboard and read content (e.g. link names/URLs, text) they cannot reach through the normal edit endpoints. Requires PatchesFixed in 5.0.8: the clipboard copy paths now also verify source-side permission ( WorkaroundsNone. Upgrade is recommended. CreditsReported by the security team at the University of Sydney ([@reporter]). Affected versions
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
+ 128 more Show less
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.10.0
3.10.0rc1
3.10.0rc2
3.10.1
3.10.1rc1
3.11.0
3.11.1
3.11.10
3.11.11
3.11.1rc1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0
3.6.0rc1
3.6.0rc3
3.6.1
3.7.0
3.7.0rc1
3.7.0rc2
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.0rc1
3.8.1
3.8.2
3.9.0
3.9.0rc1
3.9.0rc2
3.9.0rc3
4.1.0
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.1
4.1.10
4.1.11
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Fixed in
5.0.8
References
Updated Sep 10, 2026 · Source: OSV.dev |