CVE-2025-59682
- EPSS 0.08%
- Published 01.10.2025 19:15:37
- Last modified 02.10.2025 19:11:46
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal vi...
CVE-2025-59681
- EPSS 0.01%
- Published 01.10.2025 19:15:36
- Last modified 02.10.2025 19:11:46
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably craf...
CVE-2025-57833
- EPSS 0.01%
- Published 03.09.2025 00:00:00
- Last modified 08.09.2025 16:15:38
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed Query...
- EPSS 0.04%
- Published 05.06.2025 00:00:00
- Last modified 10.06.2025 18:15:32
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may l...
CVE-2025-32873
- EPSS 0.02%
- Published 08.05.2025 00:00:00
- Last modified 02.09.2025 18:58:27
An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequenc...
CVE-2025-27556
- EPSS 0.02%
- Published 02.04.2025 13:15:44
- Last modified 03.10.2025 15:34:09
An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are s...
CVE-2025-26699
- EPSS 0.42%
- Published 06.03.2025 19:15:27
- Last modified 03.10.2025 00:32:38
An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.
CVE-2024-56374
- EPSS 0.3%
- Published 14.01.2025 19:15:32
- Last modified 03.10.2025 13:16:13
An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented...
CVE-2024-53908
- EPSS 0.67%
- Published 06.12.2024 12:15:18
- Last modified 09.06.2025 19:51:17
An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an...
CVE-2024-53907
- EPSS 0.6%
- Published 06.12.2024 12:15:17
- Last modified 24.06.2025 14:55:06
An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of n...