Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A user with access to the API could see the filename and name of documents and images in private collections. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p5gm-92h4-6pv6 | Wagtail has improper restriction handling on Documents and Images API |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 11 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A user with access to the API could see the filename and name of documents and images in private collections. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4. | |
| Title | Wagtail: Improper restriction handling on Documents and Images API | |
| Weaknesses | CWE-280 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-11T14:42:22.055Z
Reserved: 2026-05-05T15:13:47.571Z
Link: CVE-2026-44201
No data.
Status : Received
Published: 2026-05-11T16:17:35.850
Modified: 2026-05-11T16:17:35.850
Link: CVE-2026-44201
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA