VDB
Sign up
MEDIUM6.9

PYSEC-2026-1303

django CMS Attributes Field Cross-site Scripting

Quick fix

PYSEC-2026-1303 — djangocms-attributes-field: upgrade to the fixed version with the command below.

pip install --upgrade 'djangocms-attributes-field>=4.0.0'

Details

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django CMS Attributes Fields allows Stored XSS.This issue affects django CMS Attributes Fields: before 4.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/djangocms-attributes-field
Introduced in: 0Fixed in: 4.0.0
Fixpip install --upgrade 'djangocms-attributes-field>=4.0.0'

References