Vulnerabilities > Torchbox > Wagtail > 2.7.3

DATE CVE VULNERABILITY TITLE RISK
2023-10-19 CVE-2023-45809 Information Exposure Through Log Files vulnerability in Torchbox Wagtail
Wagtail is an open source content management system built on Django.
network
low complexity
torchbox CWE-532
2.7
2023-04-03 CVE-2023-28837 Allocation of Resources Without Limits or Throttling vulnerability in Torchbox Wagtail
Wagtail is an open source content management system built on Django.
network
low complexity
torchbox CWE-770
4.9
2021-06-17 CVE-2021-32681 Cross-site Scripting vulnerability in Torchbox Wagtail
Wagtail is an open source content management system built on Django.
network
torchbox CWE-79
3.5
2020-07-20 CVE-2020-15118 Cross-site Scripting vulnerability in Torchbox Wagtail
In Wagtail before versions 2.7.4 and 2.9.3, when a form page type is made available to Wagtail editors through the `wagtail.contrib.forms` app, and the page template is built using Django's standard form rendering helpers such as form.as_p, any HTML tags used within a form field's help text will be rendered unescaped in the page.
network
torchbox CWE-79
3.5