{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3atorchboxwagtail/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-54263"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Wagtail (7.3.x, 7.4.x)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Wagtail"],"content_html":"\u003cp\u003eWagtail versions 7.3.0 through 7.3.2 and 7.4.0 through 7.4.1 are affected by a reflected cross-site scripting (XSS) vulnerability in the dynamic image URL generator view. The vulnerability resides within the Wagtail admin interface and allows a user with limited permissions, such as an editor, to craft a malicious URL. When a high-privilege user, such as an administrator, accesses this URL while logged into the admin interface, the malicious script is executed in their session context. This can lead to unauthorized administrative actions being performed on behalf of the victim. The flaw affects all Wagtail installations, regardless of whether the specific dynamic image serve view is enabled. Wagtail has released versions 7.3.3 and 7.4.2 to address this issue.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to the integrity of the Wagtail CMS by enabling privilege escalation through session hijacking or unauthorized administrative action. If exploited, an attacker could manipulate content, change site settings, or create new administrative accounts. The attack requires the attacker to have at least a low-privileged editor account, limiting the scope to internal threats or compromised low-level accounts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Wagtail instances to version 7.3.3 or 7.4.2 immediately to remediate CVE-2026-54263.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, implement the URL pattern workaround in 'urls.py' provided by the vendor to disable the vulnerable 'generate_url/output/' endpoint.\u003c/li\u003e\n\u003cli\u003eAudit Wagtail admin access logs for abnormal requests to '/admin/images/*/generate_url/output/' originating from non-administrator user accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T19:13:08Z","date_published":"2026-08-20T19:13:08Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wagtail-xss/","summary":"A reflected cross-site scripting (XSS) vulnerability in the Wagtail admin interface (CVE-2026-54263) allows an authenticated editor to execute arbitrary JavaScript in the context of a higher-privileged administrator.","title":"Reflected Cross-Site Scripting in Wagtail Dynamic Image URL Generator","url":"https://feed.craftedsignal.io/briefs/2026-08-wagtail-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}