Django Software Foundation
First CVE: Nov 5, 2025Active for: 1 year
30
CVEs Published
More CVEs Published than 49% of tracked CNAs
15.0
Avg CVEs / Year
More Avg CVEs / Year than 62% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Django Software Foundation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 5, 2025
8 months ago
Most Recent CVE
Jul 7, 2026
17 days ago
Top CVEs
All CVEs published by Django Software Foundation as a CNA, regardless of affected vendor or product.
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64459CRITICAL An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q | Nov 5, 2025 | 9.1 | 58 | NO | YES |
CVE-2026-1207HIGH An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to in | Feb 3, 2026 | 8.3 | 52 | NO | YES |
CVE-2026-44545HIGH daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unaut | Jun 3, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-4277CRITICAL An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
Add permissions on inline model instances were not validated on submission of
forged `POST` | Apr 7, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-53878MEDIUM An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.
`DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `Cha | Jul 7, 2026 | 6.1 | 30 | NO | NO |
CVE-2026-1312HIGH An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
`.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when | Feb 3, 2026 | 8.5 | 30 | NO | NO |
CVE-2026-1287HIGH An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
`FilteredRelation` is subject to SQL injection in column aliases via control characters, usin | Feb 3, 2026 | 8.3 | 30 | NO | NO |
CVE-2026-48588MEDIUM An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.
`UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the inc | Jul 7, 2026 | 5.3 | 29 | NO | NO |
CVE-2026-25673HIGH An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29.
`URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normali | Mar 3, 2026 | 7.5 | 29 | NO | NO |
CVE-2025-64460HIGH An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27.
Algorithmic complexity in `django.core.serializers.xml_serializer.getInnerText()` allows a re | Dec 2, 2025 | 7.5 | 29 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA30 CVEs
13%
43%
37%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network30 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (80.0%)
High6 (20.0%)
Unknown0 (0.0%)
User Interaction
None25 (83.3%)
Unknown0 (0.0%)
Required5 (16.7%)
Privileges Required
Low5 (16.7%)
High1 (3.3%)
None24 (80.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (30 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.3% of CVEs· 90th percentile
ExploitDB
1 CVE
3.3% of CVEs· 92nd percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Django Software Foundation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Django Software Foundation as a CNA — matched by CVE ID, not by organization name.