Django django是Django基金会开源的一个Web应用开发框架。 Django 5.2.17版本之前的5.2版本和6.0.8版本之前的6.0版本存在跨站脚本漏洞,该漏洞源于display_for_field函数在admin中渲染URLField值作为可点击链接时未验证URL,可能导致员工用户点击链接时遭受跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| djangoproject | Django | 6.0< 6.0.8 |
affected |
6.0.8 |
unaffected | ||
5.2< 5.2.17 |
affected | ||
5.2.17 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| djangoproject | Django | 6.0 ~ 6.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15307 | 8.8 HIGH | Server-side file-write and request forgery via spatial lookups |
| CVE-2026-15337 | 5.3 MEDIUM | Potential denial-of-service vulnerability in check_for_language() |
| CVE-2026-15830 | 5.3 MEDIUM | Potential denial-of-service vulnerability via nested geometry collections |
No comments yet