Vendor
Django Unicorn
Products
1
CVEs
3
Across products
3
Status
Private
Products
1- 3 CVEs
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-42134 | Med | 0.33 | 6.1 | 0.01 | Oct 11, 2021 | The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053. | ||
| CVE-2021-42053 | Med | 0.31 | 5.4 | 0.03 | Oct 7, 2021 | The Unicorn framework through 0.35.3 for Django allows XSS via component.name. | ||
| CVE-2026-31815 | Med | 0.27 | 5.3 | 0.00 | Mar 10, 2026 | Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and method calls. An attacker can bypass the intended… |
- risk 0.33cvss 6.1epss 0.01
The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.
- risk 0.31cvss 5.4epss 0.03
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
- risk 0.27cvss 5.3epss 0.00
Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and method calls. An attacker can bypass the intended…