Dependency scanning
Check whether wagtail is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-28223
Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interface
CVE-2026-28222
Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes
CVE-2026-28223
CVE-2026-28223
CVE-2026-28222
CVE-2026-28222
CVE-2021-32681
Cross-site Scripting in wagtail
CVE-2020-11037
Potential Observable Timing Discrepancy in Wagtail
CVE-2026-25517
Wagtail has improper permission handling on admin preview endpoints
CVE-2026-25517
Wagtail has improper permission handling on admin preview endpoints
CVE-2024-32882
Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`
CVE-2024-35228
Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`
CVE-2026-54262
CVE-2026-54262
CVE-2026-54260
CVE-2026-54260
CVE-2026-54261
CVE-2026-54261
CVE-2026-54259
CVE-2026-54259
CVE-2026-54263
CVE-2026-54263
CVE-2024-39317
Wagtail regular expression denial-of-service via search query parsing
CVE-2026-44199
Wagtail has improper permission handling when deleting form submissions
CVE-2026-44201
Wagtail has improper restriction handling on Documents and Images API
CVE-2026-44197
Wagtail has improper permission handling when comparing revisions
CVE-2026-44198
Wagtail has improper permission handling when viewing page history
CVE-2026-44200
Wagtail has improper permission handling when copying pages
CVE-2024-39317
CVE-2024-39317
CVE-2023-28836
CVE-2023-28836
CVE-2020-11037
CVE-2020-11037
CVE-2021-32681
CVE-2021-32681
CVE-2026-44201
CVE-2026-44201
CVE-2026-44200
CVE-2026-44200
CVE-2026-44199
CVE-2026-44199
CVE-2026-44198
CVE-2026-44198
CVE-2026-44197
CVE-2026-44197
CVE-2020-11001
Possible XSS attack in Wagtail
CVE-2020-15118
Cross-Site Scripting in Wagtail
CVE-2021-29434
Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields
CVE-2023-28837
Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files
CVE-2023-28836
Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views
CVE-2022-21683
Comment reply notifications sent to incorrect users
CVE-2024-35228
Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`
CVE-2024-32882
Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`
CVE-2023-45809
Wagtail vulnerable to disclosure of user names via admin bulk action views
CVE-2023-45809
CVE-2023-45809
CVE-2023-28837
CVE-2023-28837
CVE-2022-21683
CVE-2022-21683
CVE-2021-29434
CVE-2021-29434
CVE-2020-15118
CVE-2020-15118
CVE-2020-11001
CVE-2020-11001
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes