<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Django</title>
  <link>https://cvedaily.com/pages/tags/django.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/django.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Django</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[Low] CVE-2026-8404 – An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.
`djang...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8404</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-8404</strong></p>
  <p>An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-178</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-7666 – An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15.
`djang...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7666</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-7666</strong></p>
  <p>An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception. Earlier, unsupported Django series (such as 5.0.x, 4.1.x…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-6873 – An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15.
`djang...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6873</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-6873</strong></p>
  <p>An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation. Earlier,…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-48587 – An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.
`djang...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48587</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-48587</strong></p>
  <p>An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (su…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-1023</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-35193 – An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.
`djang...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35193</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-35193</strong></p>
  <p>An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django serie…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-524</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42197 – RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42197</guid>
    <pubDate>Wed, 27 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42197</strong></p>
  <p>RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execute arbitrary JavaScript in an administrator's browser session, potentially leading to full admin account takeover. The `get_user()` method in `ParticipationAdmin` renders user-controlled input using `m…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44847 – MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's web...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44847</guid>
    <pubDate>Tue, 26 May 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44847</strong></p>
  <p>MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth class unconditionally returns (None, {}), which Django REST Framework interprets as successful authentication. Combined with optional per-trigger token verification and no backend enforcement of token req…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40102 – Plane is an open-source project management tool. In versions 1.3.0 and below, Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40102</guid>
    <pubDate>Wed, 20 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40102</strong></p>
  <p>Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without validation (unlike the regular AnalyticsEndpoint, which checks against an allowlist), causing ORM Field Reference Injection. An authenticated workspace MEMBER can send GET /api/workspaces/<slug>/saved-ana…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42196 – django-s3file is a lightweight file upload input for Django and Amazon S3. Prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42196</guid>
    <pubDate>Tue, 12 May 2026 22:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42196</strong></p>
  <p>django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal attacks, where an attacker can use a modified request to escape pre-signed upload locations and have the Django application load files from random locations into request.FILES. Depending on how files are handled, this may lead to confidentiality and…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42857 – Open edX Platform enables the authoring and delivery of online learning at any s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42857</guid>
    <pubDate>Mon, 11 May 2026 18:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42857</strong></p>
  <p>Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to remove <style> tags from user-generated discussion post content. This content is rendered with Django's |safe template filter in email notification templates, allowing any enrolled student to inject arbitrary CSS into em…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44201 – Wagtail is an open source content management system built on Django. Prior to 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44201</guid>
    <pubDate>Mon, 11 May 2026 16:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44201</strong></p>
  <p>Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A user with access to the API could see the filename and name of documents and images in private collections. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-280</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44200 – Wagtail is an open source content management system built on Django. Prior to 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44200</guid>
    <pubDate>Mon, 11 May 2026 16:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44200</strong></p>
  <p>Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once coped, they'd be able to view its contents, and potentially publish it. Permissions were correctly checked for the copy destination, but not for the source page. This vulnerabil…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-280</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44199 – Wagtail is an open source content management system built on Django. Prior to 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44199</guid>
    <pubDate>Mon, 11 May 2026 16:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44199</strong></p>
  <p>Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form pages they don't have access to by crafting a form submission to delete submissions on a page they do have access to for submissions they don't. The vulnerability is not exploitable by an ordinary site visitor without ac…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-280</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44198 – Wagtail is an open source content management system built on Django. Prior to 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44198</guid>
    <pubDate>Mon, 11 May 2026 16:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44198</strong></p>
  <p>Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could still access the history report for the page, potentially resulting in disclosure of sensitive information. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-280</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44197 – Wagtail is an open source content management system built on Django. Prior to 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44197</guid>
    <pubDate>Mon, 11 May 2026 16:17:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44197</strong></p>
  <p>Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the page through the revision compare view if they knew the primary key of two revisions. This could potentially result in disclosure of sensitive information. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-280</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-44987 – SysReptor is a fully customizable pentest reporting platform. Prior to version 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44987</guid>
    <pubDate>Fri, 08 May 2026 23:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-44987</strong></p>
  <p>SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissions can change the email addresses of users with "Superuser" permissions. If the SysReptor installation has the "Forgot Password" functionality enabled (non-default), they can reset the Superusers' passwords and authenticate, if the Superuser has no MFA enabled. User managers ca…</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41654 – Weblate is a web based localization tool. Prior to version 5.17.1, an authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41654</guid>
    <pubDate>Thu, 07 May 2026 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41654</strong></p>
  <p>Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/<name>.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed s…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6907 – An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
`django.middl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6907</guid>
    <pubDate>Tue, 05 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6907</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmad…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-524</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5766 – An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
ASGI requests...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5766</guid>
    <pubDate>Tue, 05 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5766</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation.   As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMOR…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-130</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35192 – An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
Response head...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35192</guid>
    <pubDate>Tue, 05 May 2026 16:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35192</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would l…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-539</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13030 – All versions of the package django-mdeditor are vulnerable to Missing Authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13030</guid>
    <pubDate>Thu, 30 Apr 2026 06:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13030</strong></p>
  <p>All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malicious files and achieve arbitrary code execution since this endpoint lacks authentication protection and proper sanitisation of file names.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40353 – wger is a free, open-source workout and fitness manager. In versions 2.5 and bel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40353</guid>
    <pubDate>Fri, 17 Apr 2026 22:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40353</strong></p>
  <p>wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly interpolating user-controlled license fields (such as license_author) without escaping, and templates render the result using Django's |safe filter. An authenticated user can create an ingredient with a malicious license_author value…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40316 – OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40316</guid>
    <pubDate>Wed, 15 Apr 2026 23:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40316</strong></p>
  <p>OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflows/regenerate-migrations.yml workflow. The workflow uses the pull_request_target trigger to run with full GITHUB_TOKEN write permissions, copies attacker-controlled files from untrusted pull requests…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39362 – InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39362</guid>
    <pubDate>Wed, 08 Apr 2026 20:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39362</strong></p>
  <p>InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticated users can supply remote_image URLs that are fetched server-side via requests.get() with only Django's URLValidator check. There is no validation against private IP ranges or internal hostnames. Redirects are followed (allow_redirects=True), enablin…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4292 – An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4292</guid>
    <pubDate>Tue, 07 Apr 2026 15:17:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4292</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new instances to be created via forged `POST` data. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4277 – An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4277</guid>
    <pubDate>Tue, 07 Apr 2026 15:17:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4277</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank N05ec@LZU-DSLab for reporting this issue.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3902 – An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3902</guid>
    <pubDate>Tue, 07 Apr 2026 15:17:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3902</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django woul…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33034 – An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33034</guid>
    <pubDate>Tue, 07 Apr 2026 15:17:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33034</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not eval…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33033 – An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33033</guid>
    <pubDate>Tue, 07 Apr 2026 15:17:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33033</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank S…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34406 – APTRS (Automated Penetration Testing Reporting System) is a Python and Django-ba...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34406</guid>
    <pubDate>Tue, 31 Mar 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34406</strong></p>
  <p>APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. Prior to version 2.0.1, the edit_user endpoint (POST /api/auth/edituser/<pk>) allows Any user who can reach that endpoint and submit crafted permission to escalate their own account (or any other account) to superuser by includin…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-34203 – Nautobot is a Network Source of Truth and Network Automation Platform. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34203</guid>
    <pubDate>Tue, 31 Mar 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-34203</strong></p>
  <p>Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATORS setting (which defaults to an empty list, i.e., no specific rules, but can be configured in Nautobot's nautobot_config.py to apply various rules if desired).…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34231 – Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34231</guid>
    <pubDate>Tue, 31 Mar 2026 16:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34231</strong></p>
  <p>Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33530 – InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33530</guid>
    <pubDate>Thu, 26 Mar 2026 20:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33530</strong></p>
  <p>InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data operations can be hijacked to exfiltrate sensitive information from the database. The bulk operation API endpoints (e.g. `/api/part/`, `/api/stock/`, `/api/order/so/allocation/`, and others) accept a filters parameter that is passed directly to Django's ORM queryset.fil…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-202</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33153 – Tandoor Recipes is an application for managing recipes, planning meals, and buil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33153</guid>
    <pubDate>Thu, 26 Mar 2026 19:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33153</strong></p>
  <p>Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the Recipe API endpoint exposes a hidden `?debug=true` query parameter that returns the complete raw SQL query being executed, including all table names, column names, JOIN relationships, WHERE conditions (revealing access control logic), and multi-tenant space IDs. Thi…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33152 – Tandoor Recipes is an application for managing recipes, planning meals, and buil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33152</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33152</guid>
    <pubDate>Thu, 26 Mar 2026 19:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33152</strong></p>
  <p>Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework with BasicAuthentication as one of the default authentication backends. The AllAuth rate limiting configuration (ACCOUNT_RATE_LIMITS: login: 5/m/ip) only applies to the HTML-based login endpoint at /accounts/login/. Any A…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33152">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33149 – Tandoor Recipes is an application for managing recipes, planning meals, and buil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33149</guid>
    <pubDate>Thu, 26 Mar 2026 19:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33149</strong></p>
  <p>Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*' by default, which causes Django to accept any value in the HTTP Host header without validation. The application uses request.build_absolute_uri() to generate absolute URLs in multiple contexts, including invite link emails, API pagination,…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-644</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-31815 – Unicorn adds modern reactive component functionality to your Django templates. P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31815</guid>
    <pubDate>Tue, 10 Mar 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-31815</strong></p>
  <p>Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and method calls. An attacker can bypass the intended _is_public protection to modify internal attributes such as template_name or trigger protected methods. This vulnerability is fix…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30244 – Plane is an an open-source project management tool. Prior to version 1.2.2, unau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30244</guid>
    <pubDate>Fri, 06 Mar 2026 22:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30244</strong></p>
  <p>Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission classes being incorrectly configured to allow anonymous access to protected endpoints. This issue has be…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28223 – Wagtail is an open source content management system built on Django. Prior to ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28223</guid>
    <pubDate>Thu, 05 Mar 2026 20:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28223</strong></p>
  <p>Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on confirmation messages within the wagtail.contrib.simple_translation module. A user with access to the Wagtail admin area may create a page with a specially-crafted title which, when another user performs the "Translate"…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28222 – Wagtail is an open source content management system built on Django. Prior to ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28222</guid>
    <pubDate>Thu, 05 Mar 2026 20:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28222</strong></p>
  <p>Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on rendering TableBlock blocks within a StreamField. A user with access to create or edit pages containing TableBlock StreamField blocks is able to set specially-crafted class attributes on the block which run arbitrary Jav…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27982 – An open redirect vulnerability exists in django-allauth versions prior to 65.14...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27982</guid>
    <pubDate>Thu, 05 Mar 2026 06:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27982</strong></p>
  <p>An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-25674 – An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25674</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25674</guid>
    <pubDate>Tue, 03 Mar 2026 15:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-25674</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments. Earlier, unsupported D…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25674">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25673 – An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25673</guid>
    <pubDate>Tue, 03 Mar 2026 15:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25673</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause denial of service via large URL inputs containing these characters. Earlier, unsupported Django serie…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2250 – The /dbviewer/ web endpoint in METIS WIC devices is exposed without authenticati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2250</guid>
    <pubDate>Wed, 11 Feb 2026 15:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2250</strong></p>
  <p>The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing malformed requests to return verbose Django tracebacks that disclose backend source code, local file paths, and system c…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-215</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-25526 – JinJava is a Java-based template engine based on django template syntax, adapted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25526</guid>
    <pubDate>Wed, 04 Feb 2026 22:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25526</strong></p>
  <p>JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox restrictions. This issue has been patched in versions 2.7.6 and 2.8.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-25517 – Wagtail is an open source content management system built on Django. Prior to ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25517</guid>
    <pubDate>Wed, 04 Feb 2026 21:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-25517</strong></p>
  <p>Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7.3, due to a missing permission check on the preview endpoints, a user with access to the Wagtail admin and knowledge of a model's fields can craft a form submission to obtain a preview rendering of any page, snippet or site setting object for which previews are enabled, consist…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1312 – An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1312</guid>
    <pubDate>Tue, 03 Feb 2026 15:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1312</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, with dictionary expansion, used in `FilteredRelation`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affe…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1287 – An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1287</guid>
    <pubDate>Tue, 03 Feb 2026 15:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1287</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansion, as the `**kwargs` passed to `QuerySet` methods `annotate()`, `aggregate()`, `extra()`, `values()`, `values_list()`, and `alias()`. Earlier, unsupported Django…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1285 – An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1285</guid>
    <pubDate>Tue, 03 Feb 2026 15:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1285</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.chars()` and `Truncator.words()` methods (with `html=True`) and the `truncatechars_html` and `truncatewords_html` template filters allow a remote attacker to cause a potential denial-of-service via crafted inputs containing a large number of unmatched HTML end tags. Earlier, unsuppo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1207 – An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1207</guid>
    <pubDate>Tue, 03 Feb 2026 15:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1207</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14550 – An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14550</guid>
    <pubDate>Tue, 03 Feb 2026 15:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14550</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote attacker to cause a potential denial-of-service via a crafted request with multiple duplicate headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Jiyong Yang for reporting this issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13473 – An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13473</guid>
    <pubDate>Tue, 03 Feb 2026 15:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13473</strong></p>
  <p>An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Stac…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-208</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-65431 – An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ we...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65431</guid>
    <pubDate>Mon, 15 Dec 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-65431</strong></p>
  <p>An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-65430 – An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65430</guid>
    <pubDate>Mon, 15 Dec 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-65430</strong></p>
  <p>An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54307 – An issue was discovered in the Thermo Fisher Torrent Suite Django application 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54307</guid>
    <pubDate>Thu, 04 Dec 2025 15:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54307</strong></p>
  <p>An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/upload/zip/ and /configure/newupdates/offline/bundle/upload/ endpoints allow low-privilege users to upload ZIP files to the server. The plupload_file_upload function handles these file uploads and constructs the destination file path by using either the name parameter or the uploade…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54306 – An issue was discovered in the Thermo Fisher Torrent Suite Django application 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54306</guid>
    <pubDate>Thu, 04 Dec 2025 15:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54306</strong></p>
  <p>An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the network configuration functionality, stemming from insufficient input validation when processing network configuration parameters through administrative endpoints. The application allows administrators to modify the server's network configuration through the Dj…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54305 – An issue was discovered in the Thermo Fisher Torrent Suite Django application 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54305</guid>
    <pubDate>Thu, 04 Dec 2025 15:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54305</strong></p>
  <p>An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates users as ionadmin if the REMOTE_ADDR property in request.META is set to 127.0.0.1, to 127.0.1.1, or to ::1. Any user with local access to the server may bypass authentication.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54303 – The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default crede...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54303</guid>
    <pubDate>Thu, 04 Dec 2025 15:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54303</strong></p>
  <p>The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used to authenticate to default deployments with the password ionadmin. The user guide recommends changing default credentials; however, a password change policy for default administrative accounts is not enforced. Many deplo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64460 – An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64460</guid>
    <pubDate>Tue, 02 Dec 2025 16:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64460</strong></p>
  <p>An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django.core.serializers.xml_serializer.getInnerText()` allows a remote attacker to cause a potential denial-of-service attack triggering CPU and memory exhaustion via specially crafted XML input processed by the XML `Deserializer`. Earlier, unsupported Django series (such as 5.0.x, 4.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13372 – An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13372</guid>
    <pubDate>Tue, 02 Dec 2025 16:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13372</strong></p>
  <p>An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the `**kwargs` passed to `QuerySet.annotate()` or `QuerySet.alias()` on PostgreSQL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64484 – OAuth2-Proxy is an open-source tool that can act as either a standalone reverse ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64484</guid>
    <pubDate>Mon, 10 Nov 2025 22:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64484</strong></p>
  <p>OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions prior to 7.13.0, all deployments of OAuth2 Proxy in front of applications that normalize underscores to dashes in HTTP headers (e.g., WSGI-based frameworks such as Django, Flask, FastAPI, and PHP applications).…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-644</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-64459 – An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64459</guid>
    <pubDate>Wed, 05 Nov 2025 15:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-64459</strong></p>
  <p>An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluate…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64458 – An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64458</guid>
    <pubDate>Wed, 05 Nov 2025 15:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64458</strong></p>
  <p>An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is slow on Windows. As a consequence, `django.http.HttpResponseRedirect`, `django.http.HttpResponsePermanentRedirect`, and the shortcut `django.shortcuts.redirect`  were subject to a potential  denial-of-service attack via certain inputs with a very large number of Unicode character…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-59682 – An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59682</guid>
    <pubDate>Wed, 01 Oct 2025 19:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-59682</strong></p>
  <p>An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal via an archive with file paths sharing a common prefix with the target directory.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59681 – An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59681</guid>
    <pubDate>Wed, 01 Oct 2025 19:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59681</strong></p>
  <p>An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to these methods (on MySQL and MariaDB).</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48868 – Horilla is a free and open source Human Resource Management System (HRMS). An au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48868</guid>
    <pubDate>Wed, 24 Sep 2025 14:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48868</strong></p>
  <p>Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query parameter in the project_bulk_archive view. This allows privileged users (e.g., administrators) to execute arbitrary system commands on the server. While having Dja…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-59340 – jinjava is a Java-based template engine based on django template syntax, adapted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59340</guid>
    <pubDate>Wed, 17 Sep 2025 20:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-59340</strong></p>
  <p>jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.8.1, by using mapper.getTypeFactory().constructFromCanonical(), it is possible to instruct the underlying ObjectMapper to deserialize attacker-controlled input into arbitrary classes. This enables the creation of semi-arbitrary class instances without directly invoking restricte…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57833 – An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57833</guid>
    <pubDate>Wed, 03 Sep 2025 21:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57833</strong></p>
  <p>An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48432 – An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48432</guid>
    <pubDate>Thu, 05 Jun 2025 03:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48432</strong></p>
  <p>An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25111 – django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25111</guid>
    <pubDate>Sat, 31 May 2025 01:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25111</strong></p>
  <p>django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-277</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48383 – Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, inst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48383</guid>
    <pubDate>Tue, 27 May 2025 15:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48383</strong></p>
  <p>Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses like the ModelSelect2MultipleWidget and ModelSelect2Widget can leak secret access tokens across requests. This can allow users to access restricted query sets and restricted data. This issue has been patched in version 8.4.1.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-402</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-4894 – A vulnerability classified as problematic was found in calmkart Django-sso-serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4894</guid>
    <pubDate>Sun, 18 May 2025 20:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-4894</strong></p>
  <p>A vulnerability classified as problematic was found in calmkart Django-sso-server up to 057247929a94ffc358788a37ab99e391379a4d15. This vulnerability affects the function gen_rsa_keys of the file common/crypto.py. The manipulation leads to inadequate encryption strength. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. This…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-32873 – An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32873</guid>
    <pubDate>Thu, 08 May 2025 04:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-32873</strong></p>
  <p>An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27556 – An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NF...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27556</guid>
    <pubDate>Wed, 02 Apr 2025 13:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27556</strong></p>
  <p>An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-26699 – An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26699</guid>
    <pubDate>Thu, 06 Mar 2025 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-26699</strong></p>
  <p>An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-24370 – Django-Unicorn adds modern reactive component functionality to Django templates...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24370</guid>
    <pubDate>Mon, 03 Feb 2025 21:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-24370</strong></p>
  <p>Django-Unicorn adds modern reactive component functionality to Django templates. Affected versions of Django-Unicorn are vulnerable to python class pollution vulnerability. The vulnerability arises from the core functionality `set_property_value`, which can be remotely triggered by users by crafting appropriate component requests and feeding in values of second and third parameter to the vulnerab…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-56374 – An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56374</guid>
    <pubDate>Tue, 14 Jan 2025 19:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-56374</strong></p>
  <p>An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The dja…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-56113 – Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56113</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-56113</strong></p>
  <p>Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-22151 – Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22151</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-22151</strong></p>
  <p>Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydantic). The vulnerability occurs when multiple GraphQL types are mapped to the same underlying model while using the relay node interface. When que…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-56363 – APTRS (Automated Penetration Testing Reporting System) is a Python and Django-ba...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56363</guid>
    <pubDate>Mon, 23 Dec 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-56363</strong></p>
  <p>APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. In 1.0, there is a vulnerability in the web application's handling of user-supplied input that is incorporated into a Jinja2 template. Specifically, when user input is improperly sanitized or validated, an attacker can inject Jin…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-97</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-53908 – An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53908</guid>
    <pubDate>Fri, 06 Dec 2024 12:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-53908</strong></p>
  <p>An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53907 – An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53907</guid>
    <pubDate>Fri, 06 Dec 2024 12:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53907</strong></p>
  <p>An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-11406 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11406</guid>
    <pubDate>Wed, 20 Nov 2024 12:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-11406</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django CMS Attributes Fields allows Stored XSS.  This issue affects django CMS Attributes Fields: before 4.0.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-11404 – Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11404</guid>
    <pubDate>Wed, 20 Nov 2024 12:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-11404</strong></p>
  <p>Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django Filer allows Input Data Manipulation, Stored XSS.  This issue affects django Filer: from 3 before 3.3.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-11319 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11319</guid>
    <pubDate>Mon, 18 Nov 2024 12:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-11319</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).  This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52004 – MediaCMS is an open source video and media CMS, written in Python/Django and Rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52004</guid>
    <pubDate>Fri, 08 Nov 2024 23:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52004</strong></p>
  <p>MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has been prone to vulnerabilities that upon special cases can lead to remote code execution. All versions before v4.1.0 are susceptible, and users are highly recommended to upgrade. The vulnerabilities are related with insufficient input validation while uploading media content. The…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-9953 – A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9953</guid>
    <pubDate>Mon, 14 Oct 2024 22:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-9953</strong></p>
  <p>A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition when the profile is accessed. While the Django server restricts unpickling to prevent server crashes, this vulnerability could still disrupt operations.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45231 – An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45231</guid>
    <pubDate>Tue, 08 Oct 2024 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45231</strong></p>
  <p>An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45230 – An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45230</guid>
    <pubDate>Tue, 08 Oct 2024 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45230</strong></p>
  <p>An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47082 – Strawberry GraphQL is a library for creating GraphQL APIs. Prior to version 0.24...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47082</guid>
    <pubDate>Wed, 25 Sep 2024 18:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47082</strong></p>
  <p>Strawberry GraphQL is a library for creating GraphQL APIs. Prior to version 0.243.0, multipart file upload support as defined in the GraphQL multipart request specification was enabled by default in all Strawberry HTTP view integrations. This made all Strawberry HTTP view integrations vulnerable to cross-site request forgery (CSRF) attacks if users did not explicitly enable CSRF preventing securi…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42005 – An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QueryS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42005</guid>
    <pubDate>Wed, 07 Aug 2024 15:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42005</strong></p>
  <p>An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41991 – An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The ur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41991</guid>
    <pubDate>Wed, 07 Aug 2024 15:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41991</strong></p>
  <p>An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41990 – An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The ur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41990</guid>
    <pubDate>Wed, 07 Aug 2024 15:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41990</strong></p>
  <p>An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-130</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41989 – An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The fl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41989</guid>
    <pubDate>Wed, 07 Aug 2024 15:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41989</strong></p>
  <p>An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in scientific notation with a large exponent.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-41806 – The Open edX Platform is a learning management platform. Instructors can upload ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41806</guid>
    <pubDate>Thu, 25 Jul 2024 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-41806</strong></p>
  <p>The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the instructor dashboard. These files are uploaded using the django default storage. With certain storage backends, uploads may become publicly available when the uploader uses versions master, palm, olive, nutmeg, maple, lilac, koa, or juniper. The patch i…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-39317 – Wagtail is an open source content management system built on Django. A bug in Wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39317</guid>
    <pubDate>Thu, 11 Jul 2024 16:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-39317</strong></p>
  <p>Wagtail is an open source content management system built on Django. A bug in Wagtail's `parse_query_string` would result in it taking a long time to process suitably crafted inputs. When used to parse sufficiently long strings of characters without a space, `parse_query_string` would take an unexpectedly large amount of time to process, resulting in a denial of service. In an initial Wagtail ins…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39614 – An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_su...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39614</guid>
    <pubDate>Wed, 10 Jul 2024 05:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39614</strong></p>
  <p>An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-130</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-39330 – An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derive...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39330</guid>
    <pubDate>Wed, 10 Jul 2024 05:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-39330</strong></p>
  <p>An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generate_filename() without replicating the file-path validations from the parent class, potentially allow directory traversal via certain inputs during a save() call. (Built-in Storage sub-classes are unaffected.)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-39329 – An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The dj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39329</guid>
    <pubDate>Wed, 10 Jul 2024 05:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-39329</strong></p>
  <p>An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing attack involving login requests for users with an unusable password.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-208</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38875 – An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38875</guid>
    <pubDate>Wed, 10 Jul 2024 05:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38875</strong></p>
  <p>An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of brackets.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-130</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38875">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
