Skip to content
Noroxi

torchbox records

23 published records for vendor torchbox.

All records

23 records
  • Wagtail: Reflected XSS in dynamic image URL generator view

    HighCVSS 7.3No exploitEPSS 0%

    torchbox · wagtailJul 1, 2026

  • Possible XSS attack in Wagtail

    MediumCVSS 6.8No exploitEPSS 1%

    torchbox · wagtailApr 14, 2020

  • Wagtail: Improper permission handling when comparing revisions

    MediumCVSS 6.5No exploitEPSS 0%

    torchbox · wagtailMay 11, 2026

  • Wagtail: Improper permission handling in image preview

    MediumCVSS 6.5No exploitEPSS 0%

    torchbox · wagtailJul 1, 2026

  • Wagtail: Improper permission handling when copying pages

    MediumCVSS 6.5No exploitEPSS 0%

    torchbox · wagtailMay 11, 2026

  • Wagtail: Improper permission handling when deleting form submissions

    MediumCVSS 6.5No exploitEPSS 0%

    torchbox · wagtailMay 11, 2026

  • Wagtail: Improper escaping of HTML (Cross-site Scripting) on TableBlock class attributes

    MediumCVSS 6.1No exploitEPSS 1%

    torchbox · wagtailMar 5, 2026

  • Wagtail: Improper escaping of HTML (Cross-site Scripting) in simple_translation admin interface

    MediumCVSS 6.1No exploitEPSS 1%

    torchbox · wagtailMar 5, 2026

  • Improper escaping of HTML ('Cross-site Scripting') in Wagtail StreamField blocks

    MediumCVSS 5.4No exploitEPSS 1%

    torchbox · wagtailJun 17, 2021

  • Cross-Site Scripting in Wagtail

    MediumCVSS 5.4No exploitEPSS 1%

    torchbox · wagtailJul 20, 2020

  • Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views

    MediumCVSS 5.4No exploitEPSS 1%

    torchbox · wagtailApr 3, 2023

  • Wagtail: Improper restriction handling on Documents and Images API

    MediumCVSS 5.3No exploitEPSS 0%

    torchbox · wagtailMay 11, 2026

  • Wagtail has improper permission handling on admin preview endpoints

    MediumCVSS 5.1No exploitEPSS 0%

    torchbox · wagtailFeb 4, 2026

  • Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files

    MediumCVSS 4.9No exploitEPSS 1%

    torchbox · wagtailApr 3, 2023

  • Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields

    MediumCVSS 4.8No exploitEPSS 1%

    torchbox · wagtailApr 19, 2021

  • Wagtail regular expression denial-of-service via search query parsing

    MediumCVSS 4.9No exploitEPSS 1%

    torchbox · wagtailJul 11, 2024

  • Potential Observable Timing Discrepancy in Wagtail

    MediumCVSS 4.7No exploitEPSS 0%

    torchbox · wagtailApr 30, 2020

  • Comment reply notifications sent to incorrect users in wagtail

    MediumCVSS 4.3No exploitEPSS 1%

    torchbox · wagtailJan 18, 2022

  • Wagtail: Improper restriction handling on Documents and Images chosen endpoints

    MediumCVSS 4.3No exploitEPSS 0%

    torchbox · wagtailJul 1, 2026

  • Wagtail: Improper permission handling when viewing page history

    MediumCVSS 4.3No exploitEPSS 0%

    torchbox · wagtailMay 11, 2026

  • Wagtail: Pages translations can be created without page permissions when using simple_translation

    MediumCVSS 4.3No exploitEPSS 0%

    torchbox · wagtailJul 1, 2026

  • Disclosure of user names via admin bulk action views in wagtail

    LowCVSS 2.7No exploitEPSS 0%

    torchbox · wagtailOct 19, 2023

  • Wagtail: Denial of service via unbounded filter specs in the image preview

    LowCVSS 2.7No exploitEPSS 0%

    torchbox · wagtailJul 1, 2026