VulnSea

djust has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 5. The median CVSS is 7.9 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.9
Publish → KEV
Last 90 days
6 prev 0

Products

  • djust 6
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

djust vulnerabilities

CVEs affecting djust, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

GHSA-xjw9-38cr-6372High
4d ago

djust: A template binding inherits a context safety grant it never earned (XSS)

djust: A template binding inherits a context safety grant it never earned (XSS)

Twilightdjust · djustvia OSV
GHSA-9395-2g46-rj3fHigh
4d ago

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

Twilightdjust · djustvia OSV
CVE-2026-61595High· 7.7
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `thread…

Twilightdjust · djustEPSS 0.38%via NVD
CVE-2026-61593High· 8.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin …

Twilightdjust · djustEPSS 0.18%via NVD
CVE-2026-61598High· 7.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.mixins.model_binding.ModelBindingMixin` provides a default `update_model` event handler and is …

Twilightdjust · djustEPSS 0.41%via NVD
CVE-2026-55571High· 8.2
3w ago

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticate…

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

Twilightdjust · djustEPSS 0.28%via OSV
djust vulnerabilities (CVEs) · VulnSea