Skip to main content

Vendor/product archive

djangoproject / django CVEs

Beta · best-effort

154 CVEs tagged to djangoproject / django13 Critical, 46 High, 82 Medium, 13 Low, 0 Unrated.

CVE-2021-23336

Published Feb 15, 2021

The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning v…

CVSS 5.9 · Medium

CVE-2020-7471

Published Feb 3, 2020

Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14235

Published Aug 2, 2019

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to sign…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14233

Published Aug 2, 2019

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_ta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14232

Published Aug 2, 2019

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12308

Published Jun 3, 2019

An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the pr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16984

Published Oct 2, 2018

An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Djang…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12794

Published Sep 7, 2017

In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstance…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7234

Published Apr 4, 2017

A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any othe…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 154 CVEsPage 4 of 7