THREAT OPS › Threat News › [GHSA] GHSA-23m2-mghx-vqmf (high) — Wagtail: Reflected XSS in dynamic image URL generator view
[GHSA] GHSA-23m2-mghx-vqmf (high) — Wagtail: Reflected XSS in dynamic image URL generator view
GHSA-23m2-mghx-vqmf Severity: high CVE: CVE-2026-54263
Wagtail: Reflected XSS in dynamic image URL generator view
### Impact
A reflected cross-site scripting (XSS) vulnerability exists on the dynamic image URL generator view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could craft a URL that, when viewed by a user with higher privileg
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-54263cve
- https://docs.wagtail.org/en/stable/support.htmlurl
- security@wagtail.orgemail
Original source: https://github.com/advisories/GHSA-23m2-mghx-vqmf