Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
djangoproject vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2011-0697
Cross-site scripting (XSS) vulnerability in Django 1.1.x prior to 1.1.4 and 1.2.x prior to 1.2.5 might allow remote malicious users to inject arbitrary web script or HTML via a filename associated with a file upload.
Djangoproject Django 1.1
Djangoproject Django 1.1.3
Djangoproject Django 1.1.0
Djangoproject Django 1.1.2
Djangoproject Django 1.2.1
Djangoproject Django 1.2.2
Djangoproject Django 1.2.3
Djangoproject Django 1.2.4
Djangoproject Django 1.2
4.3
CVSSv2
CVE-2010-3082
Cross-site scripting (XSS) vulnerability in Django 1.2.x prior to 1.2.2 allows remote malicious users to inject arbitrary web script or HTML via a csrfmiddlewaretoken (aka csrf_token) cookie.
Djangoproject Django 1.2.2
Djangoproject Django 1.2.1
4
CVSSv2
CVE-2021-33203
Django prior to 2.2.24, 3.x prior to 3.1.12, and 3.2.x prior to 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files. Additionally, if (and only if) the default admind...
Djangoproject Django
Fedoraproject Fedora 35
4
CVSSv2
CVE-2021-23336
The package python/cpython from 0 and prior to 3.6.13, from 3.7.0 and prior to 3.7.10, from 3.8.0 and prior to 3.8.8, from 3.9.0 and prior to 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaki...
Python Python
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
Debian Debian Linux 9.0
Netapp Cloud Backup -
Netapp Snapcenter -
Netapp Ontap Select Deploy Administration Utility -
Netapp Inventory Collect Tool -
Djangoproject Django
Oracle Zfs Storage Appliance 8.8
Oracle Enterprise Manager Ops Center 12.4.0.0
Oracle Communications Offline Mediation Controller 12.0.0.3.0
Oracle Communications Pricing Design Center 12.0.0.3.0
4
CVSSv2
CVE-2019-19118
Django 2.1 prior to 2.1.15 and 2.2 prior to 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edit permissions to the inline model, would be presented with an editing UI, al...
Djangoproject Django
Fedoraproject Fedora 31
3 Github repositories
4
CVSSv2
CVE-2018-16984
An issue exists in Django 2.1 prior to 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permiss...
Djangoproject Django
4
CVSSv2
CVE-2013-0305
The administrative interface for Django 1.3.x prior to 1.3.6, 1.4.x prior to 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.
Djangoproject Django 1.3.2
Djangoproject Django 1.3.3
Djangoproject Django 1.3
Djangoproject Django 1.3.1
Djangoproject Django 1.4
Djangoproject Django 1.4.1
Djangoproject Django 1.4.2
Djangoproject Django 1.5
Canonical Ubuntu Linux 10.04
Canonical Ubuntu Linux 12.10
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 11.10
4
CVSSv2
CVE-2010-4534
The administrative interface in django.contrib.admin in Django prior to 1.1.3, 1.2.x prior to 1.2.4, and 1.3.x prior to 1.3 beta 1 does not properly restrict use of the query string to perform certain object filtering, which allows remote authenticated users to obtain sensitive i...
Djangoproject Django 0.95.1
Djangoproject Django 0.96
Djangoproject Django 0.91
Djangoproject Django 0.95
Djangoproject Django
Djangoproject Django 1.1.0
Djangoproject Django 1.0
Djangoproject Django 1.0.1
Djangoproject Django 1.0.2
Djangoproject Django 1.1
Djangoproject Django 1.2.1
Djangoproject Django 1.2.2
Djangoproject Django 1.2.3
Djangoproject Django 1.2
Djangoproject Django 1.3
3.5
CVSSv2
CVE-2014-0483
The administrative interface (contrib.admin) in Django prior to 1.4.14, 1.5.x prior to 1.5.9, 1.6.x prior to 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive i...
Opensuse Opensuse 12.3
Opensuse Opensuse 13.1
Djangoproject Django 1.5.3
Djangoproject Django 1.5.4
Djangoproject Django 1.5
Djangoproject Django 1.5.5
Djangoproject Django 1.5.6
Djangoproject Django 1.5.7
Djangoproject Django 1.5.8
Djangoproject Django 1.5.1
Djangoproject Django 1.5.2
Djangoproject Django 1.6
Djangoproject Django 1.6.1
Djangoproject Django 1.6.2
Djangoproject Django 1.6.3
Djangoproject Django 1.6.4
Djangoproject Django 1.6.5
Djangoproject Django 1.4
Djangoproject Django 1.4.4
Djangoproject Django 1.4.5
Djangoproject Django 1.4.1
Djangoproject Django 1.4.10
2.6
CVSSv2
CVE-2016-2513
The password hasher in contrib/auth/hashers.py in Django prior to 1.8.10 and 1.9.x prior to 1.9.3 allows remote malicious users to enumerate users via a timing attack involving login requests.
Djangoproject Django 1.8.9
Djangoproject Django 1.9.2
Djangoproject Django 1.9.1
Djangoproject Django 1.9
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3201
CVE-2024-4779
CVE-2024-35090
CVE-2024-5084
hard-coded
CVE-2024-4985
HTML injection
CVE-2024-33655
local file inclusion
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
NEXT »