Vulnerability index

Browse CVEs

129 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2025-48432 An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.… Django 4.2.23 / 5.1.11+ Fix from $1,6002025-06-05 MEDIUM 5.3 CVE-2025-32873EPSS 14% An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerabl… Django 4.2.21 / 5.1.9+ Fix from $1,6002025-05-08 HIGH 7.5 CVE-2025-27556 An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib… Django 5.0.14 / 5.1.8+ Fix from $1,9502025-04-02 HIGH 7.5 CVE-2025-26699 An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap templa… Django 4.2.20 / 5.0.13+ Fix from $1,9502025-03-06 HIGH 7.5 CVE-2024-56374 An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed… Django 4.2.18 / 5.0.11+ Fix from $1,9502025-01-14 CRITICAL 9.8 CVE-2024-53908 An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey… Django 4.2.17 / 5.0.10+ Fix from $2,3002024-12-06 HIGH 7.5 CVE-2024-53907 An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter a… Django 4.2.17 / 5.0.10+ Fix from $1,9502024-12-06 HIGH 7.5 CVE-2024-45230EPSS 26% An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subj… Django 4.2.16 / 5.0.9+ Fix from $1,9502024-10-08 MEDIUM 5.3 CVE-2024-45231 An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementin… Django 4.2.16 / 5.0.9+ Fix from $1,6002024-10-08 HIGH 7.5 CVE-2024-41989 An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumptio… Django 4.2.15 / 5.0.8+ Fix from $1,9502024-08-07 HIGH 7.5 CVE-2024-41990 An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential … Django 4.2.15 / 5.0.8+ Fix from $1,9502024-08-07 HIGH 7.5 CVE-2024-41991 An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget wi… Django 4.2.15 / 5.0.8+ Fix from $1,9502024-08-07 HIGH 7.3 CVE-2024-42005 An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are … Django 4.2.15 / 5.0.8+ Fix from $1,9502024-08-07 HIGH 7.5 CVE-2024-38875 An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack… Django 4.2.14 / 5.0.7+ Fix from $1,9502024-07-10 HIGH 7.5 CVE-2024-39614EPSS 29% An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-servi… Django 4.2.14 / 5.0.7+ Fix from $1,9502024-07-10 MEDIUM 5.3 CVE-2024-39329 An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows … Django 4.2.14 / 5.0.7+ Fix from $1,6002024-07-10 MEDIUM 5.3 CVE-2024-27351 In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncat… Django 3.2.25 / 4.2.11+ Fix from $1,6002024-03-15 HIGH 7.5 CVE-2024-24680 An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a po… Django 3.2.24 / 4.2.10+ Fix from $1,9502024-02-06 HIGH 7.5 CVE-2023-43665 In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with htm… Django 3.2.22 / 4.1.12+ Fix from $1,9502023-11-03 HIGH 7.5 CVE-2023-41164 In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of ser… Django 3.2.21 / 4.1.11+ Fix from $1,9502023-11-03 HIGH 7.5 CVE-2023-46695EPSS 50% An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequ… Django 3.2.23 / 4.1.13+ Fix from $1,9502023-11-02 HIGH 7.5 CVE-2023-36053 In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular express… Django 3.2.20 / 4.1.10+ Fix from $1,9502023-07-03 CRITICAL 9.8 CVE-2023-31047 In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multipl… Django 3.2.19 / 4.1.9+ Fix from $2,3002023-05-07 HIGH 7.5 CVE-2023-24580EPSS 63% An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs … Django 3.2.18 / 4.0.10+ Fix from $1,9502023-02-15 HIGH 7.5 CVE-2023-23969EPSS 47% In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repeti… Django 3.2.17 / 4.0.9+ Fix from $1,9502023-02-01 HIGH 7.5 CVE-2022-41323 In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via … Django 3.2.16 / 4.0.8+ Fix from $1,9502022-10-16 HIGH 8.8 CVE-2022-36359 An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected … Django 3.2.15 / 4.0.7+ Fix from $1,9502022-08-03 CRITICAL 9.8 CVE-2022-34265EPSS 73% An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection i… Django 3.2.14 / 4.0.6+ Fix from $2,3002022-07-04 CRITICAL 9.8 CVE-2022-28347 A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passi… Django 2.2.28 / 3.2.13+ Fix from $2,3002022-04-12 CRITICAL 9.8 CVE-2022-28346EPSS 19% An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods a… Django 2.2.28 / 3.2.13+ Fix from $2,3002022-04-12