django-cms is vulnerable to Cross-site Scripting (XSS)
77
High Risk
Affected versions of this package fail to properly sanitize user-supplied data when used inside a function that creates a page_title attribute for the specified input, leading to a stored Cross-Site Scripting (XSS) vulnerability. An attacker can exploit this by injecting malicious JavaScript or HTML into the title creation input field. This unsafe front-end rendering allows the execution of scripts in a victim's browser, potentially stealing session cookies or handling other client-side exploits.
You are affected if you are using a version that falls within the vulnerable range.
django-cms is vulnerable to Cross-site Scripting (XSS) in versions 4.1.2 - 4.1.6.
Upgrade the django-cms library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant