CVE-2026-28223
unknown
CVSS v3
—
VIR risk
—
Description
Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interface
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
References
- https://github.com/wagtail/wagtail/security/advisories/GHSA-p4v8-rw59-93cq
- https://nvd.nist.gov/vuln/detail/CVE-2026-28223
- https://github.com/wagtail/wagtail/commit/1c6f2effed68f4ccad6fbd07987e03641505f863
- https://github.com/wagtail/wagtail/commit/ba70244d376a7b1bd180ded03e827917ff410c19
- https://github.com/wagtail/wagtail/commit/d8c5900982df8ed5938ad993aa9ff69cda50f80c
- https://github.com/wagtail/wagtail/commit/ee39d39deeb7f250fe886417b24802d7e05b1143
- https://github.com/wagtail/wagtail
- https://github.com/wagtail/wagtail/releases/tag/v6.3.8
- https://github.com/wagtail/wagtail/releases/tag/v7.0.6
- https://github.com/wagtail/wagtail/releases/tag/v7.2.3
- https://github.com/wagtail/wagtail/releases/tag/v7.3.1
💬 Discuss CVE-2026-28223 on VIR Community →
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.