Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

pypi wagtail Security Advisories

Loading...
Low
GSA_kwCzR0hTQS13MnY4LXBocDQtcDhoY84AA7eE
Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`
Ecosystems: pypi
Packages: wagtail
Source: GitHub Advisory Database
Blast Radius: 8.9
Published: 3 days ago
Low
GSA_kwCzR0hTQS1mYzc1LTU4cjgtcm0zaM4AA2kA
Wagtail vulnerable to disclosure of user names via admin bulk action views
Ecosystems: pypi
Packages: wagtail
Source: GitHub Advisory Database
Blast Radius: 8.9
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS0zM3B2LXZjZ2gtamZnOc4AAyg6
Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files
Ecosystems: pypi
Packages: wagtail
Source: GitHub Advisory Database
Blast Radius: 14.5
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS01Mjg2LWYycmYtMzVjMs4AAygz
Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views
Ecosystems: pypi
Packages: wagtail
Source: GitHub Advisory Database
Blast Radius: 21.1
Published: about 1 year ago
Low
GSA_kwCzR0hTQS14cXhtLTJycG0tMzg4Oc0kJQ
Comment reply notifications sent to incorrect users
Ecosystems: pypi
Packages: wagtail
Source: GitHub Advisory Database
Blast Radius: 11.5
Published: over 2 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhmcnctaHhyNS1naHFm
Cross-site Scripting in wagtail
Ecosystems: pypi
Packages: wagtail
Source: GitHub Advisory Database
Blast Radius: 17.8
Published: almost 3 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdxNWgtZjlwNS1xN2Z4
Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields
Ecosystems: pypi
Packages: wagtail
Source: GitHub Advisory Database
Blast Radius: 20.1
Published: about 3 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTI0NzMtOWhncS1qN3h3
Cross-Site Scripting in Wagtail
Ecosystems: pypi
Packages: wagtail
Source: GitHub Advisory Database
Blast Radius: 18.8
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpqanItM2pjdy1mOHY2
Potential Observable Timing Discrepancy in Wagtail
Ecosystems: pypi
Packages: wagtail
Source: GitHub Advisory Database
Blast Radius: 20.1
Published: almost 4 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXYyd2MtcGZxMi01Y202
Possible XSS attack in Wagtail
Ecosystems: pypi
Packages: wagtail
Source: GitHub Advisory Database
Blast Radius: 19.1
Published: about 4 years ago
Statistics
Advisories: 18,369
Packages: 8,294
Repositories: 1
Ecosystems: 12
Filter by Package
tensorflow 432 tensorflow-cpu 387 tensorflow-gpu 384 django 80 apache-airflow 78 ansible 63 salt 50 apache-superset 48 Plone 45 plone 43 rdiffweb 42 Pillow 41 vyper 38 matrix-synapse 35 mlflow 31 opencv-python 30 opencv-contrib-python 30 Django 27 moin 23 langchain 18 PaddlePaddle 17 mercurial 17 cobbler 17 pillow 16 nova 15 paddlepaddle 15 notebook 15 cryptography 15 gradio 14 modoboa 14 pyftpdlib 14 keystone 14 pyload-ng 14 neutron 13 OctoPrint 12 vantage6 12 glance 11 calibreweb 11 twisted 11 urllib3 11 aiohttp 11 onionshare-cli 11 trytond 10 wagtail 10 Flask-AppBuilder 10 zope 9 opencv-contrib-python-headless 9 opencv-python-headless 9 ethyca-fides 9 waitress 9 Zope 9 kiwitcms 9 trac 8 numpy 8 python-keystoneclient 8 aubio 8 roundup 8 nautobot 8 label-studio 8 swift 7 jupyter-server 7 pysaml2 7 pgadmin4 7 lief 7 scrapy 7 ipython 7 pip 7 matrix-sydent 7 mailman 6 apache-airflow-providers-apache-hive 6 lxml 6 Zope2 6 sentry 6 tuf 6 web2py 6 horizon 6 graphite-web 6 mindsdb 6 inventree 6 bleach 5 pyspark 5 saleor 5 lmdb 5 ckan 5 requests 5 python-gnupg 5 feedparser 5 whoogle-search 5 Products.CMFPlone 5 paramiko 5 cinder 5 jupyterhub 4 tripleo-heat-templates 4 bottle 4 Radicale 4 aws-iot-device-sdk-v2 4 Pygments 4 reportlab 4 software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk 4 markdown2 4 awsiotsdk 4 nltk 4 starlette 4 nvflare 4 datasette 4 Jinja2 4 ansible-core 4 transformers 4 esphome 4 httpie 4 Flask-Security-Too 4 grpc 4 keylime 4 grpcio 4 oauthenticator 4 FreeTAKServer-UI 4 tornado 4 PyPDF2 4 buildbot 4 pretix 4 werkzeug 4 GitPython 4 omero-web 4 yt-dlp 4 jwcrypto 4 qutebrowser 4 mistune 3 Mezzanine 3 gerapy 3 SQLAlchemy 3 copyparty 3 django-helpdesk 3 Werkzeug 3 dulwich 3 pyyaml 3 sanic 3 flask 3 pandasai 3 mayan-edms 3 barbican 3 aim 3 indy-node 3 protobuf 3 ryu 3 streamlit 3 httplib2 3 sosreport 3 zenml 3 sickrage 3 rsa 3 Weblate 3 ujson 3 openvpn-monitor 3 Keystone 3 pyarrow 3 Products.PluggableAuthService 3 changedetection.io 3 ajenti 3 fava 3 Moin 3 pycrypto 3 mitmproxy 3 keyring 3 io.grpc:grpc-protobuf 3 wger 3 apache-libcloud 3 ecdsa 3 plone.app.event 3 plone.app.theming 3 plone.app.dexterity 3 plone.supermodel 3 sqlparse 3 homeassistant 3 onnx 3 asyncua 3 torchserve 3 ansible-runner 3 localstack 3 poetry 3 bitlyshortener 3 indico 3 octavia 3 slixmpp 3 jupyterlab 3 clearml 3 docassemble.webapp 3 apache-iotdb 3 asyncssh 3 quokka 3 pywasm3 3 apache-airflow-providers-apache-spark 3 ray 3 python-jose 3 pymatgen 2 pyxdg 2 openapi-python-client 2 wagtail-2fa 2 zope2 2 py 2 ctx 2