Vulnerability index

Browse CVEs

129 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Django MEDIUM 5.3
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.…

Fix: 4.2.23 / 5.1.11+
Fix from $1,600 2025-06-05
Django MEDIUM 5.3
CVE-2025-32873EPSS 14%

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerabl…

Fix: 4.2.21 / 5.1.9+
Fix from $1,600 2025-05-08
Django HIGH 7.5
CVE-2025-27556

An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib…

Fix: 5.0.14 / 5.1.8+
Fix from $1,950 2025-04-02
Django HIGH 7.5
CVE-2025-26699

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap templa…

Fix: 4.2.20 / 5.0.13+
Fix from $1,950 2025-03-06
Django HIGH 7.5
CVE-2024-56374

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed…

Fix: 4.2.18 / 5.0.11+
Fix from $1,950 2025-01-14
Django CRITICAL 9.8
CVE-2024-53908

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey…

Fix: 4.2.17 / 5.0.10+
Fix from $2,300 2024-12-06
Django HIGH 7.5
CVE-2024-53907

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter a…

Fix: 4.2.17 / 5.0.10+
Fix from $1,950 2024-12-06
Django HIGH 7.5
CVE-2024-45230EPSS 26%

An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subj…

Fix: 4.2.16 / 5.0.9+
Fix from $1,950 2024-10-08
Django MEDIUM 5.3
CVE-2024-45231

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementin…

Fix: 4.2.16 / 5.0.9+
Fix from $1,600 2024-10-08
Django HIGH 7.5
CVE-2024-41989

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumptio…

Fix: 4.2.15 / 5.0.8+
Fix from $1,950 2024-08-07
Django HIGH 7.5
CVE-2024-41990

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential …

Fix: 4.2.15 / 5.0.8+
Fix from $1,950 2024-08-07
Django HIGH 7.5
CVE-2024-41991

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget wi…

Fix: 4.2.15 / 5.0.8+
Fix from $1,950 2024-08-07
Django HIGH 7.3
CVE-2024-42005

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are …

Fix: 4.2.15 / 5.0.8+
Fix from $1,950 2024-08-07
Django HIGH 7.5
CVE-2024-38875

An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack…

Fix: 4.2.14 / 5.0.7+
Fix from $1,950 2024-07-10
Django HIGH 7.5
CVE-2024-39614EPSS 29%

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-servi…

Fix: 4.2.14 / 5.0.7+
Fix from $1,950 2024-07-10
Django MEDIUM 5.3
CVE-2024-39329

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows …

Fix: 4.2.14 / 5.0.7+
Fix from $1,600 2024-07-10
Django MEDIUM 5.3
CVE-2024-27351

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncat…

Fix: 3.2.25 / 4.2.11+
Fix from $1,600 2024-03-15
Django HIGH 7.5
CVE-2024-24680

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a po…

Fix: 3.2.24 / 4.2.10+
Fix from $1,950 2024-02-06
Django HIGH 7.5
CVE-2023-43665

In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with htm…

Fix: 3.2.22 / 4.1.12+
Fix from $1,950 2023-11-03
Django HIGH 7.5
CVE-2023-41164

In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of ser…

Fix: 3.2.21 / 4.1.11+
Fix from $1,950 2023-11-03
Django HIGH 7.5
CVE-2023-46695EPSS 50%

An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequ…

Fix: 3.2.23 / 4.1.13+
Fix from $1,950 2023-11-02
Django HIGH 7.5
CVE-2023-36053

In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular express…

Fix: 3.2.20 / 4.1.10+
Fix from $1,950 2023-07-03
Django CRITICAL 9.8
CVE-2023-31047

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multipl…

Fix: 3.2.19 / 4.1.9+
Fix from $2,300 2023-05-07
Django HIGH 7.5
CVE-2023-24580EPSS 63%

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs …

Fix: 3.2.18 / 4.0.10+
Fix from $1,950 2023-02-15
Django HIGH 7.5
CVE-2023-23969EPSS 47%

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repeti…

Fix: 3.2.17 / 4.0.9+
Fix from $1,950 2023-02-01
Django HIGH 7.5
CVE-2022-41323

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via …

Fix: 3.2.16 / 4.0.8+
Fix from $1,950 2022-10-16
Django HIGH 8.8
CVE-2022-36359

An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected …

Fix: 3.2.15 / 4.0.7+
Fix from $1,950 2022-08-03
Django CRITICAL 9.8
CVE-2022-34265EPSS 73%

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection i…

Fix: 3.2.14 / 4.0.6+
Fix from $2,300 2022-07-04
Django CRITICAL 9.8
CVE-2022-28347

A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passi…

Fix: 2.2.28 / 3.2.13+
Fix from $2,300 2022-04-12
Django CRITICAL 9.8
CVE-2022-28346EPSS 19%

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods a…

Fix: 2.2.28 / 3.2.13+
Fix from $2,300 2022-04-12