CVE-2026-93455: Batiste Django-Page-CMS

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. Attackers with low-privilege staff credentials can enumerate content identifiers and access unpublished drafts, page listings, and file paths without proper authorization checks.

Affected products

  • Batiste Django-Page-CMS: up to and including 2.0.13

Published 2026-09-18. Last modified 2026-09-22.