torchbox records
23 published records for vendor torchbox.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-280 Improper Handling of Insufficient Permissions or Privileges8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-400 Uncontrolled Resource Consumption2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-208 Observable Timing Discrepancy1
- CWE-1333 Inefficient Regular Expression Complexity1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
29Monitor | CVE-2026-54263No exploit | Wagtail: Reflected XSS in dynamic image URL generator viewtorchbox · wagtail · CWE-79 | High7.3 | — | 0.4% | Jul 1, 2026 |
27Monitor | CVE-2020-11001No exploit | Possible XSS attack in Wagtailtorchbox · wagtail · CWE-79 | Medium6.8 | — | 1.3% | Apr 14, 2020 |
26Monitor | CVE-2026-44197No exploit | Wagtail: Improper permission handling when comparing revisionstorchbox · wagtail · CWE-280 | Medium6.5 | — | 0.3% | May 11, 2026 |
26Monitor | CVE-2026-54261No exploit | Wagtail: Improper permission handling in image previewtorchbox · wagtail · CWE-280 | Medium6.5 | — | 0.3% | Jul 1, 2026 |
26Monitor | CVE-2026-44200No exploit | Wagtail: Improper permission handling when copying pagestorchbox · wagtail · CWE-280 | Medium6.5 | — | 0.3% | May 11, 2026 |
26Monitor | CVE-2026-44199No exploit | Wagtail: Improper permission handling when deleting form submissionstorchbox · wagtail · CWE-280 | Medium6.5 | — | 0.3% | May 11, 2026 |
24Monitor | CVE-2026-28222No exploit | Wagtail: Improper escaping of HTML (Cross-site Scripting) on TableBlock class attributestorchbox · wagtail · CWE-79 | Medium6.1 | — | 0.6% | Mar 5, 2026 |
24Monitor | CVE-2026-28223No exploit | Wagtail: Improper escaping of HTML (Cross-site Scripting) in simple_translation admin interfacetorchbox · wagtail · CWE-79 | Medium6.1 | — | 0.6% | Mar 5, 2026 |
21Monitor | CVE-2021-32681No exploit | Improper escaping of HTML ('Cross-site Scripting') in Wagtail StreamField blockstorchbox · wagtail · CWE-79 | Medium5.4 | — | 1.1% | Jun 17, 2021 |
21Monitor | CVE-2020-15118No exploit | Cross-Site Scripting in Wagtailtorchbox · wagtail · CWE-79 | Medium5.4 | — | 1.1% | Jul 20, 2020 |
21Monitor | CVE-2023-28836No exploit | Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin viewstorchbox · wagtail · CWE-79 | Medium5.4 | — | 0.8% | Apr 3, 2023 |
21Monitor | CVE-2026-44201No exploit | Wagtail: Improper restriction handling on Documents and Images APItorchbox · wagtail · CWE-280 | Medium5.3 | — | 0.3% | May 11, 2026 |
20Monitor | CVE-2026-25517No exploit | Wagtail has improper permission handling on admin preview endpointstorchbox · wagtail · CWE-862 | Medium5.1 | — | 0.4% | Feb 4, 2026 |
19Monitor | CVE-2023-28837No exploit | Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large filestorchbox · wagtail · CWE-400 | Medium4.9 | — | 1.1% | Apr 3, 2023 |
19Monitor | CVE-2021-29434No exploit | Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fieldstorchbox · wagtail · CWE-79 | Medium4.8 | — | 0.6% | Apr 19, 2021 |
19Monitor | CVE-2024-39317No exploit | Wagtail regular expression denial-of-service via search query parsingtorchbox · wagtail · CWE-1333 | Medium4.9 | — | 0.6% | Jul 11, 2024 |
18Monitor | CVE-2020-11037No exploit | Potential Observable Timing Discrepancy in Wagtailtorchbox · wagtail · CWE-208 | Medium4.7 | — | 0.3% | Apr 30, 2020 |
17Monitor | CVE-2022-21683No exploit | Comment reply notifications sent to incorrect users in wagtailtorchbox · wagtail · CWE-200 | Medium4.3 | — | 1.0% | Jan 18, 2022 |
17Monitor | CVE-2026-54259No exploit | Wagtail: Improper restriction handling on Documents and Images chosen endpointstorchbox · wagtail · CWE-280 | Medium4.3 | — | 0.3% | Jul 1, 2026 |
17Monitor | CVE-2026-44198No exploit | Wagtail: Improper permission handling when viewing page historytorchbox · wagtail · CWE-280 | Medium4.3 | — | 0.3% | May 11, 2026 |
17Monitor | CVE-2026-54262No exploit | Wagtail: Pages translations can be created without page permissions when using simple_translationtorchbox · wagtail · CWE-280 | Medium4.3 | — | 0.3% | Jul 1, 2026 |
10Monitor | CVE-2023-45809No exploit | Disclosure of user names via admin bulk action views in wagtailtorchbox · wagtail · CWE-200 | Low2.7 | — | 0.5% | Oct 19, 2023 |
10Monitor | CVE-2026-54260No exploit | Wagtail: Denial of service via unbounded filter specs in the image previewtorchbox · wagtail · CWE-400 | Low2.7 | — | 0.4% | Jul 1, 2026 |
- CVE-2026-5426329Monitor
Wagtail: Reflected XSS in dynamic image URL generator view
HighCVSS 7.3No exploitEPSS 0%torchbox · wagtailJul 1, 2026
- CVE-2020-1100127Monitor
Possible XSS attack in Wagtail
MediumCVSS 6.8No exploitEPSS 1%torchbox · wagtailApr 14, 2020
- CVE-2026-4419726Monitor
Wagtail: Improper permission handling when comparing revisions
MediumCVSS 6.5No exploitEPSS 0%torchbox · wagtailMay 11, 2026
- CVE-2026-5426126Monitor
Wagtail: Improper permission handling in image preview
MediumCVSS 6.5No exploitEPSS 0%torchbox · wagtailJul 1, 2026
- CVE-2026-4420026Monitor
Wagtail: Improper permission handling when copying pages
MediumCVSS 6.5No exploitEPSS 0%torchbox · wagtailMay 11, 2026
- CVE-2026-4419926Monitor
Wagtail: Improper permission handling when deleting form submissions
MediumCVSS 6.5No exploitEPSS 0%torchbox · wagtailMay 11, 2026
- CVE-2026-2822224Monitor
Wagtail: Improper escaping of HTML (Cross-site Scripting) on TableBlock class attributes
MediumCVSS 6.1No exploitEPSS 1%torchbox · wagtailMar 5, 2026
- CVE-2026-2822324Monitor
Wagtail: Improper escaping of HTML (Cross-site Scripting) in simple_translation admin interface
MediumCVSS 6.1No exploitEPSS 1%torchbox · wagtailMar 5, 2026
- CVE-2021-3268121Monitor
Improper escaping of HTML ('Cross-site Scripting') in Wagtail StreamField blocks
MediumCVSS 5.4No exploitEPSS 1%torchbox · wagtailJun 17, 2021
- CVE-2020-1511821Monitor
Cross-Site Scripting in Wagtail
MediumCVSS 5.4No exploitEPSS 1%torchbox · wagtailJul 20, 2020
- CVE-2023-2883621Monitor
Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views
MediumCVSS 5.4No exploitEPSS 1%torchbox · wagtailApr 3, 2023
- CVE-2026-4420121Monitor
Wagtail: Improper restriction handling on Documents and Images API
MediumCVSS 5.3No exploitEPSS 0%torchbox · wagtailMay 11, 2026
- CVE-2026-2551720Monitor
Wagtail has improper permission handling on admin preview endpoints
MediumCVSS 5.1No exploitEPSS 0%torchbox · wagtailFeb 4, 2026
- CVE-2023-2883719Monitor
Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files
MediumCVSS 4.9No exploitEPSS 1%torchbox · wagtailApr 3, 2023
- CVE-2021-2943419Monitor
Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields
MediumCVSS 4.8No exploitEPSS 1%torchbox · wagtailApr 19, 2021
- CVE-2024-3931719Monitor
Wagtail regular expression denial-of-service via search query parsing
MediumCVSS 4.9No exploitEPSS 1%torchbox · wagtailJul 11, 2024
- CVE-2020-1103718Monitor
Potential Observable Timing Discrepancy in Wagtail
MediumCVSS 4.7No exploitEPSS 0%torchbox · wagtailApr 30, 2020
- CVE-2022-2168317Monitor
Comment reply notifications sent to incorrect users in wagtail
MediumCVSS 4.3No exploitEPSS 1%torchbox · wagtailJan 18, 2022
- CVE-2026-5425917Monitor
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
MediumCVSS 4.3No exploitEPSS 0%torchbox · wagtailJul 1, 2026
- CVE-2026-4419817Monitor
Wagtail: Improper permission handling when viewing page history
MediumCVSS 4.3No exploitEPSS 0%torchbox · wagtailMay 11, 2026
- CVE-2026-5426217Monitor
Wagtail: Pages translations can be created without page permissions when using simple_translation
MediumCVSS 4.3No exploitEPSS 0%torchbox · wagtailJul 1, 2026
- CVE-2023-4580910Monitor
Disclosure of user names via admin bulk action views in wagtail
LowCVSS 2.7No exploitEPSS 0%torchbox · wagtailOct 19, 2023
- CVE-2026-5426010Monitor
Wagtail: Denial of service via unbounded filter specs in the image preview
LowCVSS 2.7No exploitEPSS 0%torchbox · wagtailJul 1, 2026