VendorsDjango Projectdjangoany version
Vulnerabilities

Django Project Django any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

128CVEs
CVE-2025-13372
Potential SQL injection in FilteredRelation column aliases on PostgreSQL
Published 2025-12-02 · Analyzed
4.3EPSS 0.009
CVE-2026-6873
Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie
Published 2026-06-03 · Analyzed
4.3EPSS 0.003
CVE-2010-4534
The administrative interface in django.contrib.admin in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not properly restrict use of the query string to perform certain object filtering, which allows remote authenticated users to obtain sensitive information via a series of requests containing regular expressions, as demonstrated by a created_by__password__regex parameter.
Published 2011-01-10 · Modified
4.0EPSS 0.025
CVE-2026-25674
Potential incorrect permissions on newly created file system objects
Published 2026-03-03 · Analyzed
3.7EPSS 0.003
CVE-2014-0483
The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change form page, as demonstrated by a /admin/auth/user/?pop=1&t=password URI.
Published 2014-08-26 · Modified
3.5EPSS 0.020
CVE-2026-35193
Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddleware
Published 2026-06-03 · Analyzed
3.1EPSS 0.004
CVE-2026-7666
Potential unencrypted email transmission via STARTTLS in the SMTP backend
Published 2026-06-03 · Analyzed
3.1EPSS 0.002
CVE-2026-4292
Privilege abuse in ModelAdmin.list_editable
Published 2026-04-07 · Analyzed
2.7EPSS 0.004
← Prev4 / 4