Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c4mr-889m-vgf6 | Wagtail has improper permission handling when viewing page history |
Tue, 12 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Torchbox
Torchbox wagtail |
|
| CPEs | cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Torchbox
Torchbox wagtail |
Mon, 11 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wagtail
Wagtail wagtail |
|
| Vendors & Products |
Wagtail
Wagtail wagtail |
Mon, 11 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 11 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could still access the history report for the page, potentially resulting in disclosure of sensitive information. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4. | |
| Title | Wagtail: Improper permission handling when viewing page history | |
| Weaknesses | CWE-280 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-11T15:53:39.449Z
Reserved: 2026-05-05T15:13:47.570Z
Link: CVE-2026-44198
Updated: 2026-05-11T15:53:35.729Z
Status : Analyzed
Published: 2026-05-11T16:17:35.057
Modified: 2026-05-12T15:58:41.620
Link: CVE-2026-44198
No data.
OpenCVE Enrichment
Updated: 2026-05-11T17:30:15Z
Github GHSA