Vendor
high
advisory
CSRF and Stored XSS Vulnerability in django-page-cms
1 TTP 1 CVEAn improper CSRF protection flaw in django-page-cms versions up to 2.0.13 enables attackers to force authenticated editors to inject stored XSS payloads.
django-page-cms
web-vulnerability
csrf
xss
1t
1c
critical
threat
Active Exploitation of CVE-2026-1207 in Django Framework
1 CVEA critical vulnerability, CVE-2026-1207, affecting Django versions prior to 4.2.28, 5.2.11, and 6.0.2, is actively being exploited, posing a significant risk of web server compromise and data exfiltration to organizations using the affected framework.
exploited
Django 4.2 +2
web-application
vulnerability
active-exploitation
python
django
1c