Django has 40 CVEs on record between 2020 and 2026. Disclosures have slowed: 5 in the last 90 days after 10 in the 90 before. The busiest recent month was June 2026 with 5. The median CVSS is 5.3 (medium), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 5 prev 10
Worst active — by depth score
CVE-2024-39614High· 7.5Django vulnerable to Denial of Service59CVE-2025-64458High· 7.5Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows54CVE-2025-57833High· 7.1Django is subject to SQL injection through its column aliases54CVE-2024-53908Critical· 9.8Django SQL injection in HasKey(lhs, rhs) on Oracle54CVE-2020-9402High· 8.8SQL injection in Django53
Django vulnerabilities
CVEs affecting Django, newest first. Open any entry for full detail, references, and exploit status.
40 CVEsRSS
CVE-2024-45231Low· 3.7Django allows enumeration of user e-mail addresses
Django allows enumeration of user e-mail addresses
CVE-2024-38875High· 7.5Django vulnerable to Denial of Service
Django vulnerable to Denial of Service
CVE-2024-39614High· 7.5PoCDjango vulnerable to Denial of Service
Django vulnerable to Denial of Service
CVE-2024-39330High· 7.5Django Path Traversal vulnerability
Django Path Traversal vulnerability
CVE-2024-27351Medium· 5.3Regular expression denial-of-service in Django
Regular expression denial-of-service in Django
CVE-2013-1665MediumXML External Entity (XXE) in Django
XML External Entity (XXE) in Django
CVE-2013-1664MediumXML Entity Expansion (XEE) in Django
XML Entity Expansion (XEE) in Django
CVE-2007-0404HighDjango Arbitrary Code Execution
Django Arbitrary Code Execution
CVE-2007-0405MediumDjango Improper Access Control
Django Improper Access Control
CVE-2020-9402High· 8.8SQL injection in Django
SQL injection in Django