Product
A reflected cross-site scripting (XSS) vulnerability in the Wagtail admin interface (CVE-2026-54263) allows an authenticated editor to execute arbitrary JavaScript in the context of a higher-privileged administrator.