VYPR
Medium severity4.8NVD Advisory· Published Nov 18, 2024· Updated Jun 17, 2026

CVE-2024-11319

CVE-2024-11319

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).

This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
django-cmsPyPI
>= 3.11.7, < 3.11.93.11.9
django-cmsPyPI
>= 4.1.2, < 4.1.44.1.4

Affected products

6
  • cpe:2.3:a:django-cms:django_cms:3.11.7:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:django-cms:django_cms:3.11.7:*:*:*:*:*:*:*
    • cpe:2.3:a:django-cms:django_cms:3.11.8:*:*:*:*:*:*:*
    • cpe:2.3:a:django-cms:django_cms:4.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:django-cms:django_cms:4.1.3:*:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 3.11.7, < 3.11.9
  • django CMS Association/django-cmsv5
    Range: 3.11.7

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.