CVE-2025-64460
- EPSS 0.03%
- Veröffentlicht 02.12.2025 15:15:34
- Zuletzt bearbeitet 02.12.2025 22:16:08
An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django.core.serializers.xml_serializer.getInnerText()` allows a remote attacker to cause a potential denial-of-service attack triggering...
CVE-2025-13372
- EPSS 0.01%
- Veröffentlicht 02.12.2025 15:13:35
- Zuletzt bearbeitet 02.12.2025 17:16:29
An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the `**kwargs` passed to `Quer...
CVE-2025-64459
- EPSS 0.07%
- Veröffentlicht 05.11.2025 15:15:41
- Zuletzt bearbeitet 10.11.2025 18:25:59
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictio...
CVE-2025-64458
- EPSS 0.02%
- Veröffentlicht 05.11.2025 15:15:40
- Zuletzt bearbeitet 10.11.2025 18:33:02
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is slow on Windows. As a consequence, `django.http.HttpResponseRedirect`, `django.http.HttpResponsePermanentRedirect`, and the shortcu...
CVE-2025-59682
- EPSS 0.03%
- Veröffentlicht 01.10.2025 19:15:37
- Zuletzt bearbeitet 04.11.2025 22:16:35
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal vi...
CVE-2025-59681
- EPSS 0.02%
- Veröffentlicht 01.10.2025 19:15:36
- Zuletzt bearbeitet 04.11.2025 22:16:35
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably craf...
CVE-2025-57833
- EPSS 0.01%
- Veröffentlicht 03.09.2025 00:00:00
- Zuletzt bearbeitet 04.11.2025 22:16:31
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed Query...
CVE-2025-48432
- EPSS 0.08%
- Veröffentlicht 05.06.2025 00:00:00
- Zuletzt bearbeitet 15.10.2025 17:47:56
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may l...
CVE-2025-32873
- EPSS 0.03%
- Veröffentlicht 08.05.2025 00:00:00
- Zuletzt bearbeitet 02.09.2025 18:58:27
An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequenc...
CVE-2025-27556
- EPSS 0.03%
- Veröffentlicht 02.04.2025 13:15:44
- Zuletzt bearbeitet 03.10.2025 15:34:09
An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are s...