Skip to main content

Vendor archive

djangoproject CVEs

Beta · best-effort

159 CVEs tagged to vendor djangoproject13 Critical, 49 High, 83 Medium, 14 Low, 0 Unrated.

CVE-2024-38875

Published Jul 10, 2024

An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a ver…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27351

Published Mar 15, 2024

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter ar…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24680

Published Feb 6, 2024

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service atta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46695

Published Nov 2, 2023

An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.form…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-24580

Published Feb 15, 2023

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23969

Published Feb 1, 2023

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41323

Published Oct 16, 2022

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36359

Published Aug 3, 2022

An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack tha…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34265

Published Jul 4, 2022

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2022-28347

Published Apr 12, 2022

A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-28346

Published Apr 12, 2022

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45116

Published Jan 5, 2022

An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dicts…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45115

Published Jan 5, 2022

An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityValidator incurred significant overhead in evaluating a submit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-33203

Published Jun 8, 2021

Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView vi…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 159 CVEsPage 3 of 7