CVE-2026-93456: Cross-Site Request Forgery (CSRF) in batiste django-page-cms
CVE-2026-93456 is a high-severity vulnerability in django-page-cms up to version 2.0.13. It involves a Cross-Site Request Forgery (CSRF) weakness where five admin mutation views lack CSRF protection, allowing attackers to forge requests that modify page content. Signed-in editors can be tricked into storing malicious unescaped content, leading to stored cross-site scripting (XSS) attacks affecting all visitors.
AI Analysis
Technical Summary
The django-page-cms product through version 2.0.13 exempts five administrative mutation views from CSRF protection in the pages/admin/views.py file. This exemption allows attackers to craft forged requests that modify page content without proper authorization. When signed-in editors visit a malicious page, they can be induced to store unescaped content that is rendered to all visitors, enabling stored XSS attacks. The vulnerability has a CVSS 4.0 score of 8.4, indicating high severity.
Potential Impact
Attackers can exploit this vulnerability to perform unauthorized modifications to page content via CSRF attacks. This can lead to stored cross-site scripting, where malicious scripts are injected and executed in the browsers of all visitors to the affected pages. This compromises the integrity of the content and can lead to further attacks such as session hijacking or malware distribution.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should consider restricting access to the affected admin mutation views and educating editors about the risk of visiting untrusted pages. Monitoring for suspicious content changes may also help detect exploitation attempts.
CVE-2026-93456: Cross-Site Request Forgery (CSRF) in batiste django-page-cms
Description
CVE-2026-93456 is a high-severity vulnerability in django-page-cms up to version 2.0.13. It involves a Cross-Site Request Forgery (CSRF) weakness where five admin mutation views lack CSRF protection, allowing attackers to forge requests that modify page content. Signed-in editors can be tricked into storing malicious unescaped content, leading to stored cross-site scripting (XSS) attacks affecting all visitors.
CVSS v4.0
Score 8.4high
Affected software
batiste
django-page-cms
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The django-page-cms product through version 2.0.13 exempts five administrative mutation views from CSRF protection in the pages/admin/views.py file. This exemption allows attackers to craft forged requests that modify page content without proper authorization. When signed-in editors visit a malicious page, they can be induced to store unescaped content that is rendered to all visitors, enabling stored XSS attacks. The vulnerability has a CVSS 4.0 score of 8.4, indicating high severity.
Potential Impact
Attackers can exploit this vulnerability to perform unauthorized modifications to page content via CSRF attacks. This can lead to stored cross-site scripting, where malicious scripts are injected and executed in the browsers of all visitors to the affected pages. This compromises the integrity of the content and can lead to further attacks such as session hijacking or malware distribution.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should consider restricting access to the affected admin mutation views and educating editors about the risk of visiting untrusted pages. Monitoring for suspicious content changes may also help detect exploitation attempts.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-17T23:37:43.589Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aadb77655bf5e2cf59e6814
Added to database: 09/18/2026, 22:13:10 UTC
Last enriched: 09/18/2026, 22:16:51 UTC
Last updated: 09/18/2026, 22:57:20 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.