HIGH 7.3 GitHub
CVE-2026-54263
Wagtail: Reflected XSS in dynamic image URL generator view
### Impact
A reflected cross-site scripting (XSS) vulnerability exists on the dynamic image URL generator view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could craft a URL that, when viewed by a user with higher privileges, could perform actions with that user's credentials. The vulnerability is present for all sites, even if they do not enable the [dynamic image serve view](https://docs.wagtail.org/en/stable/advanced_topics/images/
Affected Products
- pip/wagtail >= 7.3, < 7.3.3
- pip/wagtail >= 7.4, < 7.4.2
References
- https://github.com/advisories/GHSA-23m2-mghx-vqmf
- https://github.com/wagtail/wagtail/security/advisories/GHSA-23m2-mghx-vqmf
- https://nvd.nist.gov/vuln/detail/CVE-2026-54263
- https://github.com/pypa/advisory-database/tree/main/vulns/wagtail/PYSEC-2026-616.yaml
This high severity vulnerability with a CVSS score of 7.3 was published on 2026-08-20 via GitHub. Affected: pip/wagtail >= 7.3, < 7.3.3, pip/wagtail >= 7.4, < 7.4.2.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.