<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:43:56.110485+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-54262</id>
    <title>CVE-2026-54262 — Wagtail: Pages translations can be created without page permissions when using simple_translation</title>
    <updated>2026-10-03T11:43:56.142922+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> wagtail</p>
<p>Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-54262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8634-mr4j-r72c</id>
    <title>GHSA-8634-mr4j-r72c — Wagtail: Pages translations can be created without page permissions when using simple_translation</title>
    <updated>2026-10-03T11:43:56.142998+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: wagtail</p>
<p>### Impact
A low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for.</p>
<p>### Patches
Patched versions have been released as Wagtail 7.0.8, 7.3.3, 7.4.2.</p>
<p>### Workarounds
N/A</p>
<p>### Acknowledgements</p>
<p>Many thanks to @devansh3008 and @alanturing881 for reporting this issue.</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory:</p>
<p>* Visit Wagtail's [support channels](https://docs.wagtail.org/en/stable/support.html)
* Email us at [security@wagtail.org](mailto:security@wagtail.org) (view our [security policy](https://github.com/wagtail/wagtail/security/policy) for more information).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8634-mr4j-r72c"/>
  </entry>
</feed>
