CVE-2026-54623 | django-cms django CMS up to 5.0.7 Move Plugin Endpoint placeholderadmin.py get_descendants plugin_parent permission

SecurityVulns

A vulnerability was found in django-cms django CMS up to 5.0.7. It has been classified as problematic. This vulnerability affects the function get_descendants of the file cms/admin/placeholderadmin.py of the component Move Plugin Endpoint. Performing a manipulation of the argument plugin_parent results in permission issues.

This vulnerability is known as CVE-2026-54623. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More