Cross-site scripting in wagtail - CVE-2026-54263
Published: June 16, 2026
wagtail
Detailed vulnerability description
The vulnerability allows a remote user to perform actions with a victim's credentials.
The vulnerability exists due to cross-site scripting in the dynamic image URL generator view within the Wagtail admin interface when handling a crafted URL. A remote user can craft a malicious URL and trick a higher-privileged user into viewing it to perform actions with a victim's credentials.
The issue is not exploitable by an ordinary site visitor without access to the Wagtail admin.