PT-2026-39233 · Wagtail · Wagtail
Seoyoung-Kang
·
Published
2026-05-08
·
Updated
2026-05-11
·
CVE-2026-44198
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Wagtail versions prior to 7.0.7
Wagtail versions prior to 7.3.2
Wagtail versions prior to 7.4
Description
A CMS user lacking page editing permissions can access the history report for a page, which may lead to the disclosure of sensitive information.
Recommendations
Update to version 7.0.7.
Update to version 7.3.2.
Update to version 7.4.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wagtail