VulnSea

djangoproject has 9 CVEs on record between 2024 and 2026. The busiest recent month was February 2026 with 3. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-89 (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
0 prev 3

Products

  • django 9
9
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

djangoproject vulnerabilities

CVEs affecting djangoproject, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-35192Medium· 6.5⚖ disputed
4mo ago

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that …

Sunlitdjangoproject · djangoEPSS 0.54%via NVD
CVE-2026-3902High· 7.5
5mo ago

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) t…

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) t…

Twilightdjangoproject · djangoEPSS 0.44%via NVD
CVE-2026-4277Critical· 9.8
5mo ago

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported D…

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported D…

Midnightdjangoproject · djangoEPSS 0.46%via NVD
CVE-2026-1312Medium· 5.4PoC
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…

Twilightdjangoproject · djangoEPSS 0.83%via NVD
CVE-2026-1287Medium· 5.4
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansio…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansio…

Sunlitdjangoproject · djangoEPSS 0.78%via NVD
CVE-2026-1207Medium· 5.4PoC
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…

Twilightdjangoproject · djangoEPSS 13%via NVD
CVE-2025-59681High· 7.1
11mo ago

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a …

Twilightdjangoproject · djangoEPSS 0.63%via NVD
CVE-2024-39329Medium· 5.3
2y ago

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing attack involving login requests for use…

Sunlitdjangoproject · djangoEPSS 0.89%via NVD
CVE-2024-24680High· 7.5
2y ago

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

Twilightdjangoproject · djangoEPSS 1.6%via NVD
djangoproject vulnerabilities (CVEs) · VulnSea