CVE-2026-16213

Summary

A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in cleartext storage of sensitive information. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
Fantomas42django-blog-zinnia0.1affected
Fantomas42django-blog-zinnia0.2affected
Fantomas42django-blog-zinnia0.3affected
Fantomas42django-blog-zinnia0.4affected
Fantomas42django-blog-zinnia0.5affected
Fantomas42django-blog-zinnia0.6affected
Fantomas42django-blog-zinnia0.7affected
Fantomas42django-blog-zinnia0.8affected
Fantomas42django-blog-zinnia0.9affected
Fantomas42django-blog-zinnia0.10affected
Fantomas42django-blog-zinnia0.11affected
Fantomas42django-blog-zinnia0.12affected
Fantomas42django-blog-zinnia0.13affected
Fantomas42django-blog-zinnia0.14affected
Fantomas42django-blog-zinnia0.15affected
Fantomas42django-blog-zinnia0.16affected
Fantomas42django-blog-zinnia0.17affected
Fantomas42django-blog-zinnia0.18affected
Fantomas42django-blog-zinnia0.19affected
Fantomas42django-blog-zinnia0.20affected

Weaknesses

  • CWE-312: Cleartext Storage of Sensitive Information
  • CWE-310: Cryptographic Issues

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References