CVE-2026-93455: Batiste Django-Page-CMS
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. Attackers with low-privilege staff credentials can enumerate content identifiers and access unpublished drafts, page listings, and file paths without proper authorization checks.
Affected products
- Batiste Django-Page-CMS: up to and including 2.0.13
Published 2026-09-18. Last modified 2026-09-22.