CVE-2013-1665Medium▾ SunlitXML External Entity (XXE) in Django
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.9 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
4.6%
4.6% → 4.6%
The XML libraries for Python as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
django >= 1.3.0, < 1.3.6django >= 1.4.0, < 1.4.4Upgrade to a patched release:
django 1.3.6django 1.4.4Connected by shared product, vendor, weakness, or advisory.
CVE-2013-1664MediumXML Entity Expansion (XEE) in Django
CVE-2026-5766Medium· 5.3Django has an Improper Handling of Length Parameter Inconsistency
CVE-2024-27351Medium· 5.3Regular expression denial-of-service in Django
CVE-2025-64460MediumDjango is vulnerable to DoS via XML serializer text extraction
CVE-2025-13372Medium· 4.3Django is vulnerable to SQL injection in column aliases
CVE-2025-64458High· 7.5Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows