CVE-2024-11319

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS). This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.

medium 4.8 CVSS 3.1
Published: Nov 18, 2024
Modified: Jun 2, 2026
Vendor: Django-Cms
Product: Django Cms
Versions: 3.11.7,3.11.8,4.1.2,4.1.3

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).

This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.

References