- CVE-2026-54259: Improper restriction handling on Documents and Images chosen endpoints
- CVE-2026-54260: Denial of service via unbounded filter specs in the image preview
- CVE-2026-54261: Improper permission handling in image preview
- CVE-2026-54262: Pages translations can be created without page permissions when using simple_translation
- CVE-2026-54263: Reflected XSS in dynamic image URL generator view