VYPR

Unicorn

by Django Unicorn

Source repositories

CVEs (3)

  • CVE-2021-42134MedOct 11, 2021
    risk 0.33cvss 6.1epss 0.01

    The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.

  • CVE-2021-42053MedOct 7, 2021
    risk 0.31cvss 5.4epss 0.03

    The Unicorn framework through 0.35.3 for Django allows XSS via component.name.

  • CVE-2026-31815MedMar 10, 2026
    risk 0.27cvss 5.3epss 0.00

    Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and method calls. An attacker can bypass the intended…