django vulnerabilities
CVEs whose affected-version data names the django package (npm, pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
49 CVEsRSS
CVE-2025-48432Medium· 4.0Django Improper Output Neutralization for Logs vulnerability
Django Improper Output Neutralization for Logs vulnerability
CVE-2025-32873Medium· 5.3PoCDjango has a denial-of-service possibility in strip_tags()
Django has a denial-of-service possibility in strip_tags()
CVE-2025-26699Medium· 5.0Django vulnerable to Allocation of Resources Without Limits or Throttling
Django vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2024-56374Medium· 5.8Django has a potential denial-of-service vulnerability in IPv6 validation
Django has a potential denial-of-service vulnerability in IPv6 validation
CVE-2024-53908Critical· 9.8Django SQL injection in HasKey(lhs, rhs) on Oracle
Django SQL injection in HasKey(lhs, rhs) on Oracle
CVE-2024-53907High· 7.5Django denial-of-service in django.utils.html.strip_tags()
Django denial-of-service in django.utils.html.strip_tags()
CVE-2024-45231Low· 3.7Django allows enumeration of user e-mail addresses
Django allows enumeration of user e-mail addresses
CVE-2024-39329Medium· 5.3An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14
An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing attack involving login requests for use…
CVE-2024-38875High· 7.5Django vulnerable to Denial of Service
Django vulnerable to Denial of Service
CVE-2024-39614High· 7.5PoCDjango vulnerable to Denial of Service
Django vulnerable to Denial of Service
CVE-2024-39330High· 7.5Django Path Traversal vulnerability
Django Path Traversal vulnerability
CVE-2024-27351Medium· 5.3Regular expression denial-of-service in Django
Regular expression denial-of-service in Django
CVE-2024-24680High· 7.5An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2
An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.
CVE-2013-1665MediumXML External Entity (XXE) in Django
XML External Entity (XXE) in Django
CVE-2013-1664MediumXML Entity Expansion (XEE) in Django
XML Entity Expansion (XEE) in Django
CVE-2007-0404HighDjango Arbitrary Code Execution
Django Arbitrary Code Execution
CVE-2007-0405MediumDjango Improper Access Control
Django Improper Access Control
CVE-2020-9402High· 8.8SQL injection in Django
SQL injection in Django
CVE-2019-11358Medium· 6.1⚠ ExploitedPoCXSS in jQuery as used in Drupal, Backdrop CMS, and other products
XSS in jQuery as used in Drupal, Backdrop CMS, and other products