๐Ÿ” CVE Alert

CVE-2026-28223

MEDIUM 6.1

Wagtail: Improper escaping of HTML (Cross-site Scripting) in simple_translation admin interface

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on confirmation messages within the wagtail.contrib.simple_translation module. A user with access to the Wagtail admin area may create a page with a specially-crafted title which, when another user performs the "Translate" action, causes arbitrary JavaScript code to run. This could lead to performing actions with that user's credentials. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been patched in versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1.

CWE CWE-79
Vendor wagtail
Product wagtail
Published Mar 5, 2026
Last Updated Mar 6, 2026
Stay Ahead of the Next One

Get instant alerts for wagtail wagtail

Be the first to know when new medium vulnerabilities affecting wagtail wagtail are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

wagtail / wagtail
< 6.3.8 >= 6.4rc1, < 7.0.6 >= 7.1rc1, < 7.2.3 >= 7.3rc1, < 7.3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wagtail/wagtail/security/advisories/GHSA-p4v8-rw59-93cq github.com: https://github.com/wagtail/wagtail/commit/1c6f2effed68f4ccad6fbd07987e03641505f863 github.com: https://github.com/wagtail/wagtail/commit/ba70244d376a7b1bd180ded03e827917ff410c19 github.com: https://github.com/wagtail/wagtail/commit/d8c5900982df8ed5938ad993aa9ff69cda50f80c github.com: https://github.com/wagtail/wagtail/commit/ee39d39deeb7f250fe886417b24802d7e05b1143 github.com: https://github.com/wagtail/wagtail/releases/tag/v6.3.8 github.com: https://github.com/wagtail/wagtail/releases/tag/v7.0.6 github.com: https://github.com/wagtail/wagtail/releases/tag/v7.2.3 github.com: https://github.com/wagtail/wagtail/releases/tag/v7.3.1