Wagtail Improper Permission Handling in Page History Access Vulnerability

Vulnerability

A vulnerability exists in Wagtail versions prior to 7.0.7, 7.3.2, and 7.4, allowing CMS users without editing rights to access the history report of a page. This could lead to the unintentional disclosure of sensitive information.

Impact

Exploitation of this vulnerability could result in unauthorized access to page history, potentially disclosing sensitive information.

Remediation

Users can upgrade to Wagtail versions 7.0.7, 7.3.2, or 7.4 to address this vulnerability. For more information, Wagtail's support channels or the security email contact can be used.

Added: May 11, 2026, 4:34 PM
Updated: May 11, 2026, 4:34 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
5.4
remediation
7.7
relevance
8.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.