Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
djangoproject django vulnerabilities and exploits
(subscribe to this query)
7.4
CVSSv3
CVE-2016-2512
The utils.http.is_safe_url function in Django prior to 1.8.10 and 1.9.x prior to 1.9.3 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authenticat...
Djangoproject Django 1.8.9
Djangoproject Django 1.9.1
Djangoproject Django 1.9
Djangoproject Django 1.9.2
3.1
CVSSv3
CVE-2016-2513
The password hasher in contrib/auth/hashers.py in Django prior to 1.8.10 and 1.9.x prior to 1.9.3 allows remote malicious users to enumerate users via a timing attack involving login requests.
Djangoproject Django 1.8.9
Djangoproject Django 1.9.1
Djangoproject Django 1.9
Djangoproject Django 1.9.2
NA
CVE-2013-0305
The administrative interface for Django 1.3.x prior to 1.3.6, 1.4.x prior to 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.
Djangoproject Django 1.3.1
Djangoproject Django 1.3
Djangoproject Django 1.3.2
Djangoproject Django 1.3.3
Djangoproject Django 1.4
Djangoproject Django 1.4.2
Djangoproject Django 1.4.1
Djangoproject Django 1.5
Canonical Ubuntu Linux 11.10
Canonical Ubuntu Linux 12.10
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 10.04
NA
CVE-2013-0306
The form library in Django 1.3.x prior to 1.3.6, 1.4.x prior to 1.4.4, and 1.5 before release candidate 2 allows remote malicious users to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_n...
Djangoproject Django 1.3.1
Djangoproject Django 1.3
Djangoproject Django 1.3.2
Djangoproject Django 1.3.3
Djangoproject Django 1.4
Djangoproject Django 1.4.2
Djangoproject Django 1.4.1
Djangoproject Django 1.5
Canonical Ubuntu Linux 11.10
Canonical Ubuntu Linux 12.10
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 10.04
NA
CVE-2015-5145
validators.URLValidator in Django 1.8.x prior to 1.8.3 allows remote malicious users to cause a denial of service (CPU consumption) via unspecified vectors.
Djangoproject Django 1.8.2
Djangoproject Django 1.8.1
Djangoproject Django 1.8.0
NA
CVE-2013-4249
Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x prior to 1.5.2 and 1.6.x prior to 1.6 beta 2 allows remote malicious users to inject arbitrary web script or HTML via a URLField.
Djangoproject Django 1.5
Djangoproject Django 1.5.1
Djangoproject Django 1.6
7.5
CVSSv3
CVE-2018-6188
django.contrib.auth.forms.AuthenticationForm in Django 2.0 prior to 2.0.2, and 1.11.8 and 1.11.9, allows remote malicious users to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether ...
Djangoproject Django 2.0
Djangoproject Django 2.0.1
Djangoproject Django 1.11.8
Djangoproject Django 1.11.9
Canonical Ubuntu Linux 17.10
NA
CVE-2015-2241
Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django prior to 1.7.6 and 1.8 prior to 1.8b2 allows remote malicious users to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @pr...
Djangoproject Django
Djangoproject Django 1.8
NA
CVE-2010-3082
Cross-site scripting (XSS) vulnerability in Django 1.2.x prior to 1.2.2 allows remote malicious users to inject arbitrary web script or HTML via a csrfmiddlewaretoken (aka csrf_token) cookie.
Djangoproject Django 1.2.1
Djangoproject Django 1.2.2
NA
CVE-2015-3982
The session.flush function in the cached_db backend in Django 1.8.x prior to 1.8.2 does not properly flush the session, which allows remote malicious users to hijack user sessions via an empty string in the session key.
Djangoproject Django 1.8.1
Djangoproject Django 1.8.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-30065
CVE-2024-5843
CVE-2024-30080
code execution
CVE-2024-4577
CVE-2024-26169
wireless
remote code execution
CVE-2024-36103
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »