CVE Explorer
CVE-2026-25517
Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7.3, due to a missing permission check on the preview endpoints, a user with access to the Wagtail admin and knowledge of a model's fields can craft a form submission to obtain a preview rendering of any page, snippet or site setting object for which previews are enabled, consisting of any data of the user's choosing. The existing data of the object itself is not exposed, but de
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"wagtail","vendor":"wagtail","versions":[{"status":"affected","version":"< 6.3.6"},{"status":"affected","version":">= 6.4rc1, < 7.0.4"},{"status":"affected","version":">= 7.1rc1, < 7.1.3"},{"status":"affected","version":">= 7.2rc1, < 7.2.2"},{"status":"affected","version":"= 7.3rc1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e8ae40dc149717e789ff3ccecef8914a104f661db220dec3cbdd116c016a1363 · sha256:6103d88ced84841e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.1,"baseSeverity":"MEDIUM","privilegesRequired":"HIGH","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e8ae40dc149717e789ff3ccecef8914a104f661db220dec3cbdd116c016a1363 · sha256:6103d88ced84841e… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e8ae40dc149717e789ff3ccecef8914a104f661db220dec3cbdd116c016a1363 · sha256:6103d88ced84841e… · /containers/cna/problemTypes/0/descriptions/0
Source references
6 source assertions{"name":"https://github.com/wagtail/wagtail/commit/01fd3477365a193e6a8270311defb76e890d2719","tags":["x_refsource_MISC"],"url":"https://github.com/wagtail/wagtail/commit/01fd3477365a193e6a8270311defb76e890d2719"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e8ae40dc149717e789ff3ccecef8914a104f661db220dec3cbdd116c016a1363 · sha256:6103d88ced84841e… · /containers/cna/references/1
{"name":"https://github.com/wagtail/wagtail/commit/5f09b6da61e779b0e8499bdbba52bf2f7bd3241f","tags":["x_refsource_MISC"],"url":"https://github.com/wagtail/wagtail/commit/5f09b6da61e779b0e8499bdbba52bf2f7bd3241f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e8ae40dc149717e789ff3ccecef8914a104f661db220dec3cbdd116c016a1363 · sha256:6103d88ced84841e… · /containers/cna/references/2
{"name":"https://github.com/wagtail/wagtail/commit/73f070dbefbd3b39ea6649ce36bd2d2a6eef2190","tags":["x_refsource_MISC"],"url":"https://github.com/wagtail/wagtail/commit/73f070dbefbd3b39ea6649ce36bd2d2a6eef2190"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e8ae40dc149717e789ff3ccecef8914a104f661db220dec3cbdd116c016a1363 · sha256:6103d88ced84841e… · /containers/cna/references/3
{"name":"https://github.com/wagtail/wagtail/commit/7dfe8de5f8b3f112c73c87b6729197db16454915","tags":["x_refsource_MISC"],"url":"https://github.com/wagtail/wagtail/commit/7dfe8de5f8b3f112c73c87b6729197db16454915"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e8ae40dc149717e789ff3ccecef8914a104f661db220dec3cbdd116c016a1363 · sha256:6103d88ced84841e… · /containers/cna/references/4
{"name":"https://github.com/wagtail/wagtail/commit/dd824023a031f1b82a6b6f83a97a5c73391b7c03","tags":["x_refsource_MISC"],"url":"https://github.com/wagtail/wagtail/commit/dd824023a031f1b82a6b6f83a97a5c73391b7c03"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e8ae40dc149717e789ff3ccecef8914a104f661db220dec3cbdd116c016a1363 · sha256:6103d88ced84841e… · /containers/cna/references/5
{"name":"https://github.com/wagtail/wagtail/security/advisories/GHSA-4qvv-g3vr-m348","tags":["x_refsource_CONFIRM"],"url":"https://github.com/wagtail/wagtail/security/advisories/GHSA-4qvv-g3vr-m348"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e8ae40dc149717e789ff3ccecef8914a104f661db220dec3cbdd116c016a1363 · sha256:6103d88ced84841e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.