VYPR

Django

by Djangoproject

pypi: django

Source repositories

CVEs (163)

  • CVE-2021-28658MedApr 6, 2021
    risk 0.35cvss 5.3epss 0.04

    In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.

  • CVE-2019-19118MedDec 2, 2019
    risk 0.35cvss 6.5epss 0.02

    Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edit permissions to the inline model, would be presented with an editing UI,…

  • CVE-2019-12781MedJul 1, 2019
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words,…

  • CVE-2018-14574MedAug 3, 2018
    risk 0.34cvss 6.1epss 0.17

    django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.

  • CVE-2017-12794MedSep 7, 2017
    risk 0.34cvss 6.1epss 0.15

    In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cross-site scripting attack. This vulnerability shouldn't affect most production…

  • CVE-2026-15920MedAug 4, 2026
    risk 0.33cvss 6.1epss 0.00

    An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on…

  • CVE-2026-53878MedJul 7, 2026
    risk 0.33cvss 6.1epss 0.00

    An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header…

  • CVE-2025-26699MedMar 6, 2025
    risk 0.33cvss 5.0epss 0.01

    An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

  • CVE-2022-22818MedFeb 3, 2022
    risk 0.33cvss 6.1epss 0.03

    The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.

  • CVE-2021-32052MedMay 6, 2021
    risk 0.33cvss 6.1epss 0.03

    In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur.…

  • CVE-2020-13596MedJun 3, 2020
    risk 0.33cvss 6.1epss 0.03

    An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

  • CVE-2019-12308MedJun 3, 2019
    risk 0.33cvss 6.1epss 0.03

    An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database,…

  • CVE-2017-7234MedApr 4, 2017
    risk 0.33cvss 6.1epss 0.02

    A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.

  • CVE-2017-7233MedApr 4, 2017
    risk 0.33cvss 6.1epss 0.03

    Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they…

  • CVE-2020-13254MedJun 3, 2020
    risk 0.32cvss 5.9epss 0.06

    An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.

  • CVE-2025-27556MedApr 2, 2025
    risk 0.31cvss 5.8epss 0.01

    An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to a potential…

  • CVE-2024-56374MedJan 14, 2025
    risk 0.31cvss 5.8epss 0.02

    An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions…

  • CVE-2026-1207MedFeb 3, 2026
    risk 0.29cvss 5.4epss 0.13

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x,…

  • CVE-2025-32873MedMay 8, 2025
    risk 0.29cvss 5.3epss 0.14

    An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags.…

  • CVE-2016-2048MedFeb 8, 2016
    risk 0.29cvss 5.5epss 0.02

    Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

Page 4 of 9