CVE-2026-54623 | django-cms django CMS up to 5.0.7 Move Plugin Endpoint placeholderadmin.py get_descendants plugin_parent permission
A vulnerability was found in django-cms django CMS up to 5.0.7. It has been classified as problematic. This vulnerability affects the function get_descendants of the file cms/admin/placeholderadmin.py of the component Move Plugin Endpoint. Performing a manipulation of the argument plugin_parent results in permission issues.
This vulnerability is known as CVE-2026-54623. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More