Django Software Foundation

First CVE: Nov 5, 2025Active for: 1 year
30
CVEs Published
More CVEs Published than 49% of tracked CNAs
15.0
Avg CVEs / Year
More Avg CVEs / Year than 62% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Django Software Foundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 5, 2025
8 months ago
Most Recent CVE
Jul 7, 2026
17 days ago

Top CVEs

All CVEs published by Django Software Foundation as a CNA, regardless of affected vendor or product.

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q
Nov 5, 20259.158NOYES
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to in
Feb 3, 20268.352NOYES
daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unaut
Jun 3, 20267.531NONO
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST`
Apr 7, 20269.831NONO
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `Cha
Jul 7, 20266.130NONO
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when
Feb 3, 20268.530NONO
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, usin
Feb 3, 20268.330NONO
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the inc
Jul 7, 20265.329NONO
An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normali
Mar 3, 20267.529NONO
An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django.core.serializers.xml_serializer.getInnerText()` allows a re
Dec 2, 20257.529NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA30 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network30 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (80.0%)
High6 (20.0%)
Unknown0 (0.0%)
User Interaction
None25 (83.3%)
Unknown0 (0.0%)
Required5 (16.7%)
Privileges Required
Low5 (16.7%)
High1 (3.3%)
None24 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.3% of CVEs· 90th percentile
ExploitDB
1 CVE
3.3% of CVEs· 92nd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Django Software Foundation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Django Software Foundation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs