Browse all 3 CVE security advisories affecting DjangoCRM. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-71240 | DjangoCRM - Unauthenticated Open Redirect via toggle_default_sorting next_url Parameter — django-crmCWE-601 | 4.3 | Medium | 2026-08-05 |
| CVE-2026-71239 | DjangoCRM - Server-Side Template Injection in Mass Mail Message Rendering — django-crmCWE-1336 | 8.1 | High | 2026-08-05 |
| CVE-2026-71238 | DjangoCRM - Hardcoded Django SECRET_KEY Enables Session and CSRF Token Forgery — django-crmCWE-798 | 9.1 | Critical | 2026-08-05 |
This page lists every published CVE security advisory associated with DjangoCRM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.