PatchSiren

batiste CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH batiste CVE published 2026-09-18

CVE-2026-93456

CVE-2026-93456 is a high-severity vulnerability in django-page-cms through 2.0.13, allowing attackers to forge requests that modify page content due to the exemption of five admin mutation views from CSRF protection. Signed-in editors visiting a malicious page can be tricked into storing unescaped content that renders to all visitors, enabling stored cross-site scripting attacks.