HIGH 7.3 GitHub

CVE-2026-54263

Wagtail: Reflected XSS in dynamic image URL generator view

### Impact A reflected cross-site scripting (XSS) vulnerability exists on the dynamic image URL generator view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could craft a URL that, when viewed by a user with higher privileges, could perform actions with that user's credentials. The vulnerability is present for all sites, even if they do not enable the [dynamic image serve view](https://docs.wagtail.org/en/stable/advanced_topics/images/

Affected Products

References

Published: 2026-08-20 · Source: GitHub · Feed updated: 2026-08-20
This high severity vulnerability with a CVSS score of 7.3 was published on 2026-08-20 via GitHub. Affected: pip/wagtail >= 7.3, < 7.3.3, pip/wagtail >= 7.4, < 7.4.2.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.