Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-6186

34
FAUCET Score

CVE-2016-6186 is a Cross-site Scripting (XSS) vulnerability in Django versions prior to 1.8.14, 1.9.8, and 1.10rc1, specifically within the admin interface's RelatedObjectLookups.js. This medium-severity vulnerability (CVSS 6.1) allows remote attackers to inject malicious web script or HTML due to unsafe use of Element.innerHTML, requiring user interaction. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry exists for a related Django CMS vulnerability, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
<= 1.8.13CPE matchmatch criteria
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
1.9CPE matchmatch criteria
cpe:2.3:a:djangoproject:django:1.9:*:*:*:*:*:*:*
1.9.0CPE matchmatch criteria
cpe:2.3:a:djangoproject:django:1.9.0:rc1:*:*:*:*:*:*
1.9.1CPE matchmatch criteria
cpe:2.3:a:djangoproject:django:1.9.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.1MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.0

Exploit Intelligence

EPSS Score
5.54%
Probability of exploitation in next 30 days
EPSS Percentile
92.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-40129 · Jul 20, 2016
This CVE's current EPSS score of 0.0554 is in the 96th percentile among its peer group of 26,234 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: djangoFixed in: 1.8.14
pippatch availablevia ghsa
Product: djangoFixed in: 1.9.8
pippatch availablevia ghsa
Product: djangoFixed in: 1.10rc1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7Fixed in: python-django-0:1.8.14-1.el7ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 8.0 (Liberty)Fixed in: python-django-0:1.8.14-1.el7ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 8.0 Operational Tools for RHEL 7Fixed in: python-django-0:1.8.14-1.el7ost
View patch
redhatend of lifevia redhat_api
Product: Red Hat Ceph Storage 1.3Fixed in: Django
redhatend of lifevia redhat_api
Product: Red Hat Subscription Asset ManagerFixed in: Django

Vendor Advisories (2)

pipGHSA-c8c8-9472-w52hmedium

Django Cross-site scripting Vulnerability

May 14, 2022
redhatCVE-2016-6186Moderate

django: XSS in admin's add/change related popup

Jul 18, 2016

References

packetstormsecurity.com / files/137965/Django-3.3.0-Script-Insertion.html
VDB Entry
rhn.redhat.com / errata/RHSA-2016-1594.html
rhn.redhat.com / errata/RHSA-2016-1595.html
rhn.redhat.com / errata/RHSA-2016-1596.html
seclists.org / fulldisclosure/2016/Jul/53
Mailing ListPatch
github.com / django/django/commit/d03bf6fe4e9bf5b07de62c1a271c4b41a7d3d158
Patch
github.com / django/django/commit/f68e5a99164867ab0e071a936470958ed867479d
Patch
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/DMLLFAUT4J4IP4P2KI4NOVWRMHA22WUJ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/KHHPN6MISX5I6UTXQHYLPTLEEUE6WDXW
djangoproject.com / weblog/2016/jul/18/security-releases
PatchVendor Advisory
exploit-db.com / exploits/40129
debian.org / security/2016/dsa-3622
Third Party Advisory
securityfocus.com / archive/1/538947/100/0/threaded
securityfocus.com / bid/92058
securitytracker.com / id/1036338
VDB Entry
ubuntu.com / usn/USN-3039-1
Third Party Advisory
vulnerability-lab.com / get_content.php
PatchThird Party Advisory