THREAT OPS › Threat News › [GHSA] GHSA-hvq6-2r72-p2x7 (medium) — django CMS: Stored XSS in edit-mode plugin exception rendering
[GHSA] GHSA-hvq6-2r72-p2x7 (medium) — django CMS: Stored XSS in edit-mode plugin exception rendering
GHSA-hvq6-2r72-p2x7 Severity: medium CVE: CVE-2026-75526
django CMS: Stored XSS in edit-mode plugin exception rendering
## Summary
When plugin rendering fails in edit mode, django CMS renders a `cms-rendering-exception` block so editors can see that a placeholder could not be rendered. Older code built that block's heading by interpolating the exception message, placeholder/source strings, and
Indicators of compromise
- CVE-2026-75526cve
Original source: https://github.com/advisories/GHSA-hvq6-2r72-p2x7