Skip to main content

Vendor archive

djangoproject CVEs

Beta · best-effort

159 CVEs tagged to vendor djangoproject13 Critical, 49 High, 83 Medium, 14 Low, 0 Unrated.

CVE-2020-35681

Published Feb 22, 2021

Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handl…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23336

Published Feb 15, 2021

The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning v…

CVSS 5.9 · Medium

CVE-2020-7471

Published Feb 3, 2020

Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14235

Published Aug 2, 2019

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to sign…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14233

Published Aug 2, 2019

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_ta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14232

Published Aug 2, 2019

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12308

Published Jun 3, 2019

An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the pr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16984

Published Oct 2, 2018

An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Djang…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 159 CVEsPage 4 of 7