Количество 775
Количество 775
GHSA-4rrr-2h4v-f3j9
Django has Inefficient Algorithmic Complexity
GHSA-4mq2-gc4j-cmw6
Django Template Engine Vulnerable to XSS
GHSA-4c42-4rxm-x6qf
Django Denial of Service Vulnerability in the authentication framework
GHSA-4894-5vqc-6r2r
Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget
GHSA-46x4-9jmv-jc8p
Django Access Restrictions Bypass
GHSA-3jqw-crqj-w8qw
Denial of service in django
GHSA-3f2c-jm6v-cr35
Django DNS Rebinding Vulnerability
GHSA-37hp-765x-j95x
Django open redirect and possible XSS attack via user-supplied numeric redirect URLs
GHSA-33mw-q7rj-mjwj
Django has Inefficient Algorithmic Complexity
GHSA-337x-4q8g-prc5
Improper Input Validation in Django
GHSA-2mcm-79hx-8fxw
Django has Observable Timing Discrepancy
GHSA-2hrw-hx67-34x6
Resource exhaustion in Django
GHSA-2gwj-7jmv-h26r
SQL Injection in Django
GHSA-2f9x-5v75-3qv4
Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters
GHSA-296w-6qhq-gf92
Django denial of service via file upload naming
GHSA-2655-q453-22f9
Django Allows Arbitrary URL Generation
CVE-2026-1312
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, with dictionary expansion, used in `FilteredRelation`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Solomon Kebede for reporting this issue.
CVE-2026-1312
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, with dictionary expansion, used in `FilteredRelation`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Solomon Kebede for reporting this issue.
CVE-2026-1312
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4. ...
CVE-2026-1287
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansion, as the `**kwargs` passed to `QuerySet` methods `annotate()`, `aggregate()`, `extra()`, `values()`, `values_list()`, and `alias()`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Solomon Kebede for reporting this issue.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4rrr-2h4v-f3j9 Django has Inefficient Algorithmic Complexity | 0% Низкий | 6 дней назад | ||
GHSA-4mq2-gc4j-cmw6 Django Template Engine Vulnerable to XSS | CVSS3: 9.3 | 2% Низкий | около 2 лет назад | |
GHSA-4c42-4rxm-x6qf Django Denial of Service Vulnerability in the authentication framework | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-4894-5vqc-6r2r Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-46x4-9jmv-jc8p Django Access Restrictions Bypass | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3jqw-crqj-w8qw Denial of service in django | CVSS3: 7.5 | 2% Низкий | больше 7 лет назад | |
GHSA-3f2c-jm6v-cr35 Django DNS Rebinding Vulnerability | CVSS3: 8.1 | 3% Низкий | больше 3 лет назад | |
GHSA-37hp-765x-j95x Django open redirect and possible XSS attack via user-supplied numeric redirect URLs | CVSS3: 6.1 | 1% Низкий | около 7 лет назад | |
GHSA-33mw-q7rj-mjwj Django has Inefficient Algorithmic Complexity | 0% Низкий | 6 дней назад | ||
GHSA-337x-4q8g-prc5 Improper Input Validation in Django | CVSS3: 6.5 | 1% Низкий | около 7 лет назад | |
GHSA-2mcm-79hx-8fxw Django has Observable Timing Discrepancy | 0% Низкий | 6 дней назад | ||
GHSA-2hrw-hx67-34x6 Resource exhaustion in Django | CVSS3: 7.5 | 25% Средний | почти 3 года назад | |
GHSA-2gwj-7jmv-h26r SQL Injection in Django | CVSS3: 9.8 | 2% Низкий | почти 4 года назад | |
GHSA-2f9x-5v75-3qv4 Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters | CVSS3: 5.3 | 1% Низкий | около 7 лет назад | |
GHSA-296w-6qhq-gf92 Django denial of service via file upload naming | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2655-q453-22f9 Django Allows Arbitrary URL Generation | CVSS3: 7.5 | 4% Низкий | больше 3 лет назад | |
CVE-2026-1312 An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, with dictionary expansion, used in `FilteredRelation`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Solomon Kebede for reporting this issue. | CVSS3: 5.4 | 0% Низкий | 6 дней назад | |
CVE-2026-1312 An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, with dictionary expansion, used in `FilteredRelation`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Solomon Kebede for reporting this issue. | CVSS3: 5.4 | 0% Низкий | 6 дней назад | |
CVE-2026-1312 An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4. ... | CVSS3: 5.4 | 0% Низкий | 6 дней назад | |
CVE-2026-1287 An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansion, as the `**kwargs` passed to `QuerySet` methods `annotate()`, `aggregate()`, `extra()`, `values()`, `values_list()`, and `alias()`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Solomon Kebede for reporting this issue. | CVSS3: 5.4 | 0% Низкий | 6 дней назад |
Уязвимостей на страницу