django-cms is vulnerable to Cross-Site Scripting (XSS)
72
High Risk
Affected versions are vulnerable to a stored cross-site scripting vulnerability in the admin URL uniqueness validation logic. User-controlled values were inserted into HTML error messages without proper escaping and marked as safe, allowing low-privileged CMS users to inject arbitrary JavaScript into the admin interface and potentially hijack sessions or perform actions as other administrators.
You are affected if you are using a version that falls within the vulnerable range.
django-cms is vulnerable to Cross-Site Scripting (XSS) in versions 3.5.0 - 5.0.6.
Upgrade the django-cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant