SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-54625

MEDIUM · CVSS 4.8 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability in django CMS allows for cache poisoning due to the page cache mechanism ignoring certain request headers declared by plugins, leading to potential content leakage between users. Specifically, when CMS_PAGE_CACHE is enabled, an unauthenticated attacker can manipulate the cache, causing one visitor to receive another's personalized content based on header variations like Country-Code. Organizations using affected versions of django CMS, particularly those with plugins that vary content based on request headers, should prioritize upgrading to versions 5.0.8 or 5.1.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54625
Severity
MEDIUM
CVSS
4.8
EPSS
0.15%

Original NVD Description

django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site, language, path, and timezone but not the declared header values. Although set_page_cache adds those names to the response Vary header, get_page_cache retrieves the first stored variant under the same header-agnostic key. When CMS_PAGE_CACHE is enabled and a plugin varies content on a header such as Country-Code, one visitor can receive another visitor’s request-specific content, and an unauthenticated attacker can prime the cache with attacker-chosen content. This issue is fixed in versions 5.0.8 and 5.1.0.