Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Django — Vulnerabilities & Security Advisories 40

All 40 CVE vulnerabilities found in Django, with AI-generated Chinese analysis, references, and POCs.

This page aggregates historical security vulnerabilities associated with the Django web framework, a Python-based open-source web application framework developed by the Django Software Foundation. The collection compiles documented security flaws, including cross-site scripting, remote code execution, and authentication bypass issues, covering disclosures from the framework’s early public releases through the present day. Readers can use this aggregation to track the vendor's security advisories, understand specific weakness classes such as injection or path traversal, and examine the complete vulnerability history for Django to identify recurring patterns in its security posture.

Vendor: djangoproject

CVE ID Title CVSS Severity Published
CVE-2026-15920 Potential cross-site scripting via URLField values in the admin CWE-83 6.1 Medium 2026-08-04
CVE-2026-15830 Potential denial-of-service vulnerability via nested geometry collections CWE-674 5.3 Medium 2026-08-04
CVE-2026-15337 Potential denial-of-service vulnerability in check_for_language() CWE-789 5.3 Medium 2026-08-04
CVE-2026-15307 Server-side file-write and request forgery via spatial lookups CWE-73 8.8 High 2026-08-04
CVE-2026-53878 Header injection possibility since DomainNameValidator accepted newlines in input CWE-144 6.1 Medium 2026-07-07
CVE-2026-53877 Heap buffer over-read in GDALRaster CWE-805 4.8 Medium 2026-07-07
CVE-2026-48588 Potential exposure of private data via cached Set-Cookie response CWE-524 4.2 Low 2026-07-07
CVE-2026-48587 Potential exposure of private data via whitespace padding in Vary header CWE-1023 3.1 Low 2026-06-03
CVE-2026-35193 Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddleware CWE-524 3.1 Low 2026-06-03
CVE-2026-8404 Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddleware CWE-178 3.1 Low 2026-06-03
CVE-2026-7666 Potential unencrypted email transmission via STARTTLS in the SMTP backend CWE-319 3.1 Low 2026-06-03
CVE-2026-6873 Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie CWE-347 3.1 Low 2026-06-03
CVE-2026-35192 Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST CWE-539 7.6 - 2026-05-05
CVE-2026-6907 Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware CWE-524 4.3 Medium 2026-05-05
CVE-2026-5766 Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass CWE-130 5.3 Medium 2026-05-05
CVE-2026-33034 Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass CWE-770 7.5AI High AI 2026-04-07
CVE-2026-33033 Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload CWE-407 5.3AI Medium AI 2026-04-07
CVE-2026-4292 Privilege abuse in ModelAdmin.list_editable CWE-862 9.1AI Critical AI 2026-04-07
CVE-2026-4277 Privilege abuse in GenericInlineModelAdmin CWE-862 9.8AI Critical AI 2026-04-07
CVE-2026-3902 ASGI header spoofing via underscore/hyphen conflation CWE-290 5.3AI Medium AI 2026-04-07
CVE-2026-25674 Potential incorrect permissions on newly created file system objects CWE-362 6.5 - 2026-03-03
CVE-2026-25673 Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows CWE-400 7.5AI High AI 2026-03-03
CVE-2025-14550 Potential denial-of-service vulnerability via repeated headers when using ASGI CWE-407 7.5 - 2026-02-03
CVE-2026-1312 Potential SQL injection via QuerySet.order_by and FilteredRelation CWE-89 9.8 - 2026-02-03
CVE-2026-1287 Potential SQL injection in column aliases via control characters CWE-89 9.8 - 2026-02-03
CVE-2026-1285 Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods CWE-407 7.5 - 2026-02-03
CVE-2026-1207 Potential SQL injection via raster lookups on PostGIS CWE-89 9.8 - 2026-02-03
CVE-2025-13473 Username enumeration through timing difference in mod_wsgi authentication handler CWE-208 3.7 - 2026-02-03
CVE-2025-64460 Potential denial-of-service vulnerability in XML serializer text extraction CWE-407 7.5AI High AI 2025-12-02
CVE-2025-13372 Potential SQL injection in FilteredRelation column aliases on PostgreSQL CWE-89 9.8AI Critical AI 2025-12-02

All 40 known CVE vulnerabilities affecting Django with full Chinese analysis, references, and POCs where available.