django has 39 CVEs on record between 2020 and 2026. Disclosures have slowed: 4 in the last 90 days after 10 in the 90 before. The busiest recent month was June 2026 with 5. The median CVSS is 5.3 (medium), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 4 prev 10
Products
- django 39
39
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2024-39614High· 7.5Django vulnerable to Denial of Service59CVE-2025-64458High· 7.5Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows54CVE-2025-57833High· 7.1Django is subject to SQL injection through its column aliases54CVE-2024-53908Critical· 9.8Django SQL injection in HasKey(lhs, rhs) on Oracle54CVE-2020-9402High· 8.8SQL injection in Django53
django vulnerabilities
CVEs affecting django, newest first. Open any entry for full detail, references, and exploit status.
39 CVEsRSS
CVE-2024-38875High· 7.5Django vulnerable to Denial of Service
Django vulnerable to Denial of Service
▾ Twilightdjango · djangoEPSS 1.2%via OSV
CVE-2024-39614High· 7.5PoCDjango vulnerable to Denial of Service
Django vulnerable to Denial of Service
▾ Midnightdjango · djangoEPSS 29%via OSV
CVE-2024-39330High· 7.5Django Path Traversal vulnerability
Django Path Traversal vulnerability
▾ Twilightdjango · djangoEPSS 1.0%via OSV
CVE-2024-27351Medium· 5.3Regular expression denial-of-service in Django
Regular expression denial-of-service in Django
▾ Sunlitdjango · djangoEPSS 1.9%via OSV
CVE-2013-1665MediumXML External Entity (XXE) in Django
XML External Entity (XXE) in Django
▾ Sunlitdjango · djangoEPSS 4.6%via OSV
CVE-2013-1664MediumXML Entity Expansion (XEE) in Django
XML Entity Expansion (XEE) in Django
▾ Sunlitdjango · djangoEPSS 4.9%via OSV
CVE-2007-0404HighDjango Arbitrary Code Execution
Django Arbitrary Code Execution
▾ Twilightdjango · djangoEPSS 1.7%via OSV
CVE-2007-0405MediumDjango Improper Access Control
Django Improper Access Control
▾ Sunlitdjango · djangoEPSS 1.3%via OSV
CVE-2020-9402High· 8.8SQL injection in Django
SQL injection in Django
▾ Twilightdjango · djangoEPSS 23%via OSV