Djangoproject

Django

136 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.69%
  • Veröffentlicht 06.12.2024 12:15:18
  • Zuletzt bearbeitet 09.06.2025 19:51:17

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an...

  • EPSS 1.04%
  • Veröffentlicht 06.12.2024 12:15:17
  • Zuletzt bearbeitet 24.06.2025 14:55:06

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of n...

  • EPSS 2.72%
  • Veröffentlicht 08.10.2024 16:15:11
  • Zuletzt bearbeitet 17.03.2025 15:15:41

An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of charact...

  • EPSS 0.24%
  • Veröffentlicht 08.10.2024 16:15:11
  • Zuletzt bearbeitet 17.03.2025 18:15:17

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending passwor...

  • EPSS 1.39%
  • Veröffentlicht 07.08.2024 15:15:56
  • Zuletzt bearbeitet 04.11.2025 17:16:03

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in scientific notation with a large exponent.

  • EPSS 1.33%
  • Veröffentlicht 07.08.2024 15:15:56
  • Zuletzt bearbeitet 04.11.2025 17:16:03

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.

  • EPSS 0.91%
  • Veröffentlicht 07.08.2024 15:15:56
  • Zuletzt bearbeitet 04.11.2025 17:16:03

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very large number...

  • EPSS 0.34%
  • Veröffentlicht 07.08.2024 15:15:56
  • Zuletzt bearbeitet 04.11.2025 17:16:04

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.

  • EPSS 0.33%
  • Veröffentlicht 10.07.2024 05:15:12
  • Zuletzt bearbeitet 04.11.2025 17:15:54

An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of brackets.

  • EPSS 0.17%
  • Veröffentlicht 10.07.2024 05:15:12
  • Zuletzt bearbeitet 04.11.2025 17:15:54

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing attack involving login requests for users with an un...