Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 25 AUG 2026

Alibaba Dragonwell Project · AUTOMATIC DISCOVERY

Wagtail 1.13 LTS

Wagtail is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

Product overview

Wagtail is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductWagtail
Release1.13 LTS
End of Active supportApril 2019
End of SupportApril 2019
Date precisionMonth

Known exploited vulnerabilities

Catalogue updated 11 Sep 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

No CISA known-exploited entries currently match this mapped product family.

This does not mean the product has no vulnerabilities.

Package vulnerability advisories

Checked 12 Sep 2026

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

CVE-2023-28836High severity

Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views

pkg:pypi/wagtailFixed: 4.1.4, 4.2.2

OSV record
CVE-2021-29434High severity

Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields

pkg:pypi/wagtailFixed: 2.11.7, 2.12.4

OSV record
CVE-2026-55468Medium severity

Wagtail: Improper restriction handling on Pages admin API

pkg:pypi/wagtailFixed: 7.0.9, 7.3.4, 7.4.3, 8.0rc2

OSV record
CVE-2024-35228Medium severity

Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`

pkg:pypi/wagtailFixed: 6.0.5, 6.1.2

OSV record
CVE-2023-28837Medium severity

Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files

pkg:pypi/wagtailFixed: 4.2.2, 4.1.4

OSV record
CVE-2024-32882Low severity

Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`

pkg:pypi/wagtailFixed: 6.0.3

OSV record
CVE-2026-55468Unknown severity

Wagtail: Improper restriction handling on Pages admin API

pkg:pypi/wagtailFixed: 7.0.9, 7.3.4, 7.4.3, 8.0rc2

OSV record

Source evidence

PRIMARYManual

Wagtail official lifecycle source

Version | Release date | Active support | Security support | 1.13 LTS | October 2017 | April 2019 | April 2019

Publisher identity used by product-specific official-source collectors.

First collected 25 Aug 2026 · Last collected 25 Aug 2026 · Review state accepted

Open official vendor source