Skip to main content

Vendor archive

djangoproject CVEs

Beta · best-effort

158 CVEs tagged to vendor djangoproject13 Critical, 49 High, 82 Medium, 14 Low, 0 Unrated.

CVE-2017-12794

Published Sep 7, 2017

In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstance…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7234

Published Apr 4, 2017

A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any othe…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7233

Published Apr 4, 2017

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these re…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6186

Published Aug 5, 2016

Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2513

Published Apr 8, 2016

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login reques…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2512

Published Apr 8, 2016

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2048

Published Feb 8, 2016

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8213

Published Dec 7, 2015

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive appl…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5145

Published Jul 14, 2015

validators.URLValidator in Django 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3982

Published Jun 2, 2015

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2241

Published Mar 12, 2015

Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0222

Published Jan 16, 2015

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by sub…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0220

Published Jan 16, 2015

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote at…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0219

Published Jan 16, 2015

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) characte…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4104

Published Oct 27, 2014

The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 101-125 of 158 CVEsPage 5 of 7