CVE-2026-93455
django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. Attackers with low-privilege staff credentials can enumerate content identifiers and access unpublished drafts, page listings, and file paths without proper authorization checks.
- Published Sep 18, 2026
- CVSS 7.1 high
- 0.5% chance of exploitation in the next 30 days (EPSS)