cbcvebase.

Djangoproject Django vulnerabilities

165 known vulnerabilities affecting djangoproject/django.

Total CVEs
165
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL14HIGH52MEDIUM93LOW6

Vulnerabilities

Page 9 of 9
CVE-2008-2302P4MEDIUM≥ 0.91, < 0.91.2≥ 0.95, < 0.95.3+1 more2022-05-01
CVE-2008-2302 [MEDIUM] CWE-79 Django Cross-site scripting (XSS) vulnerability Django Cross-site scripting (XSS) vulnerability Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.
ghsaosv
CVE-2014-0483P4LOWCVSS 3.5v1.5v1.5.1+27 more2014-08-26
CVE-2014-0483 [LOW] CWE-264 CVE-2014-0483: The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x befo The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change form page
ghsanvdosv
CVE-2026-7666P4LOWCVSS 3.1≥ 5.2, < 5.2.15≥ 6.0, < 6.0.62026-06-03
CVE-2026-7666 [LOW] CWE-319 CVE-2026-7666: An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception. Earlier, unsu
ghsanvd
CVE-2026-4292P4LOWCVSS 2.7≥ 4.2, < 4.2.30≥ 5.2, < 5.2.13+1 more2026-04-07
CVE-2026-4292 [LOW] CWE-862 CVE-2026-4292: An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changel An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new instances to be created via forged `POST` data. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank
ghsanvdosv
CVE-2007-5712P4HIGH≥ 0.96.0, < 0.96.1≥ 0.95, < 0.95.2+1 more2022-05-01
CVE-2007-5712 [HIGH] CWE-400 Django vulnerable to Denial of Service via i18n middleware component Django vulnerable to Denial of Service via i18n middleware component The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.
ghsaosv
Djangoproject Django vulnerabilities | cvebase