Логотип exploitDog
bind:"CVE-2026-1207"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2026-1207"

Количество 9

Количество 9

ubuntu логотип

CVE-2026-1207

около 2 месяцев назад

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2026-1207

около 2 месяцев назад

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-1207

около 2 месяцев назад

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2026-1207

около 2 месяцев назад

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4. ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-mwm9-4648-f68q

около 2 месяцев назад

Django has an SQL Injection issue

EPSS: Низкий
fstec логотип

BDU:2026-03466

около 2 месяцев назад

Уязвимость программной платформы для веб-приложений Django, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнить произвольный код

CVSS3: 5.4
EPSS: Низкий
redos логотип

ROS-20260310-73-0045

21 день назад

Уязвимость python-django

CVSS3: 5.4
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20184-1

около 2 месяцев назад

Security update for python-Django

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0440-1

около 2 месяцев назад

Security update for python-Django

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-1207

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 5.4
5%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-1207

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 8.3
5%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-1207

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 5.4
5%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-1207

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4. ...

CVSS3: 5.4
5%
Низкий
около 2 месяцев назад
github логотип
GHSA-mwm9-4648-f68q

Django has an SQL Injection issue

5%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2026-03466

Уязвимость программной платформы для веб-приложений Django, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнить произвольный код

CVSS3: 5.4
5%
Низкий
около 2 месяцев назад
redos логотип
ROS-20260310-73-0045

Уязвимость python-django

CVSS3: 5.4
5%
Низкий
21 день назад
suse-cvrf логотип
openSUSE-SU-2026:20184-1

Security update for python-Django

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0440-1

Security update for python-Django

около 2 месяцев назад

Уязвимостей на страницу