THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hvq6-2r72-p2x7 (medium) — django CMS: Stored XSS in edit-mode plugin exception rendering

[GHSA] GHSA-hvq6-2r72-p2x7 (medium) — django CMS: Stored XSS in edit-mode plugin exception rendering

medgithub_advisoriesPublished 2026-08-20

GHSA-hvq6-2r72-p2x7 Severity: medium CVE: CVE-2026-75526

django CMS: Stored XSS in edit-mode plugin exception rendering

## Summary

When plugin rendering fails in edit mode, django CMS renders a `cms-rendering-exception` block so editors can see that a placeholder could not be rendered. Older code built that block's heading by interpolating the exception message, placeholder/source strings, and

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hvq6-2r72-p2x7