Vulnerability index

Browse CVEs

129 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Django HIGH 7.5
CVE-2022-23833EPSS 49%

An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart …

Fix: 2.2.27 / 3.2.12+
Fix from $1,950 2022-02-03
Django MEDIUM 6.1
CVE-2022-22818

The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This …

Fix: 2.2.27 / 3.2.12+
Fix from $1,600 2022-02-03
Django HIGH 7.5
CVE-2021-45115

An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityValidator incurred significant o…

Fix: 2.2.26 / 3.2.11+
Fix from $1,950 2022-01-05
Django HIGH 7.5
CVE-2021-45116

An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variab…

Fix: 2.2.26 / 3.2.11+
Fix from $1,950 2022-01-05
Django MEDIUM 5.3
CVE-2021-45452

Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed…

Fix: 2.2.26 / 3.2.11+
Fix from $1,600 2022-01-05
Django HIGH 7.3
CVE-2021-44420

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access con…

Fix: 2.2.25 / 3.1.14+
Fix from $1,950 2021-12-08
Django CRITICAL 9.8
CVE-2021-35042EPSS 44%

Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web applic…

Fix: 3.1.13 / 3.2.5+
Fix from $2,300 2021-07-02
Django HIGH 7.5
CVE-2021-33571EPSS 5%

In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit…

Fix: 2.2.24 / 3.1.12+
Fix from $1,950 2021-06-08
Django MEDIUM 6.1
CVE-2021-32052

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless t…

Fix: 2.2.22 / 3.1.10+
Fix from $1,600 2021-05-06
Django HIGH 7.5
CVE-2021-31542EPSS 5%

In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via upl…

Fix: 2.2.21 / 3.1.9+
Fix from $1,950 2021-05-05
Django MEDIUM 5.3
CVE-2021-28658

In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably cr…

Fix: 2.2.20 / 3.0.14+
Fix from $1,600 2021-04-06
Channels HIGH 7.4
CVE-2020-35681

Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.Asg…

Fix: 3.0.3+
Fix from $1,950 2021-02-22
Django MEDIUM 5.3
CVE-2021-3281EPSS 8%

In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "sta…

Fix: 2.2.18 / 3.0.12+
Fix from $1,600 2021-02-02
Django HIGH 7.5
CVE-2020-24583

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMIS…

Fix: 2.2.16 / 3.0.10+
Fix from $1,950 2020-09-01
Django HIGH 7.5
CVE-2020-24584

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level direc…

Fix: 2.2.16 / 3.0.10+
Fix from $1,950 2020-09-01
Django MEDIUM 6.1
CVE-2020-13596

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were n…

Fix: 2.2.13 / 3.0.7+
Fix from $1,600 2020-06-03
Django MEDIUM 5.9
CVE-2020-13254EPSS 6%

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing…

Fix: 2.2.13 / 3.0.7+
Fix from $1,600 2020-06-03
Django HIGH 8.8
CVE-2020-9402EPSS 23%

Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS fu…

Fix: 1.11.29 / 2.2.11+
Fix from $1,950 2020-03-05
Django CRITICAL 9.8
CVE-2020-7471EPSS 65%

Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in…

Fix: 1.11.28 / 2.2.10+
Fix from $2,300 2020-02-03
Django CRITICAL 9.8
CVE-2019-19844EPSS 35%

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing…

Fix: 1.11.27 / 2.2.9+
Fix from $2,300 2019-12-18
Django MEDIUM 6.5
CVE-2019-19118

Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user …

Fix: 2.1.15 / 2.2.8+
Fix from $1,600 2019-12-02
Django CRITICAL 9.8
CVE-2019-14234EPSS 48%

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, …

Fix: 1.11.23 / 2.1.11+
Fix from $2,300 2019-08-09
Django HIGH 7.5
CVE-2019-14235

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding…

Fix: 1.11.23 / 2.1.11+
Fix from $1,950 2019-08-02
Django HIGH 7.5
CVE-2019-14232

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and wo…

Fix: 1.11.23 / 2.1.11+
Fix from $1,950 2019-08-02
Django HIGH 7.5
CVE-2019-14233

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLPars…

Fix: 1.11.23 / 2.1.11+
Fix from $1,950 2019-08-02
Django MEDIUM 5.3
CVE-2019-12781

An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the S…

Fix: 1.11.22 / 2.1.10+
Fix from $1,600 2019-07-01
Django MEDIUM 6.1
CVE-2019-12308

An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the Admin…

Fix: 1.11.21 / 2.1.9+
Fix from $1,600 2019-06-03
Django HIGH 7.5
CVE-2019-6975EPSS 5%

Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied va…

Fix: 1.11.19 / 2.0.11+
Fix from $1,950 2019-02-11
Django MEDIUM 6.5
CVE-2019-3498

In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Down…

Fix: 1.11.18 / 2.0.10+
Fix from $1,600 2019-01-09
Django MEDIUM 6.1
CVE-2018-14574EPSS 25%

django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.

Fix: 1.11.15 / 2.0.8+
Fix from $1,600 2018-08-03