Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 09 May 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers can inject malicious code inside a PDF file. When a user clicks the document in the CMS interface, the payload executes. | Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers can inject malicious code inside a PDF file. When a user clicks the document in the CMS interface, the payload executes. NOTE: this is disputed by the Supplier because "It has been well documented that when serving uploaded files using a method outside of Wagtail (which admittedly is the default), it requires additional configuration from the developer, because Wagtail cannot control how these are served. ... For example, if a Wagtail instance is configured to upload files into AWS S3, Wagtail cannot control the permissions on how they're served, nor any headers used when serving them (a limitation of S3)." |
References |
|
Thu, 08 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Wed, 07 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers can inject malicious code inside a PDF file. When a user clicks the document in the CMS interface, the payload executes. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-09T13:32:10.146Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-45388

Updated: 2025-05-08T15:12:57.213Z

Status : Awaiting Analysis
Published: 2025-05-07T19:16:08.680
Modified: 2025-05-09T14:15:37.813
Link: CVE-2025-45388

No data.

Updated: 2025-07-12T16:01:42Z