Django is a widely used Python web framework where the disclosed vulnerability surface centers on the Slippers template component and reflects input-sanitization challenges inherent to dynamic HTML generation. The recurring signal is cross-site scripting vulnerability in template rendering, a class of flaw endemic to web frameworks and templating engines. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Django over time
Signals from CVEs in this vendor scope (165 CVEs).
165 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34265CRITICAL An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a k | Jul 4, 2022 | 9.8 | 80 | NO | YES |
CVE-2021-35042CRITICAL Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application. | Jul 2, 2021 | 9.8 | 67 | NO | YES |
CVE-2020-7471CRITICAL Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer | Feb 3, 2020 | 9.8 | 67 | NO | NO |
CVE-2019-19844CRITICAL Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after cas | Dec 18, 2019 | 9.8 | 62 | NO | YES |
CVE-2025-64459CRITICAL An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q | Nov 5, 2025 | 9.1 | 58 | NO | YES |
CVE-2023-24580HIGH An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of p | Feb 15, 2023 | 7.5 | 57 | NO | NO |
CVE-2019-14234CRITICAL An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for djang | Aug 9, 2019 | 9.8 | 57 | NO | NO |
CVE-2026-1207HIGH An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to in | Feb 3, 2026 | 8.3 | 54 | NO | YES |
CVE-2022-23833HIGH An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infini | Feb 3, 2022 | 7.5 | 52 | NO | NO |
CVE-2023-23969HIGH In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a p | Feb 1, 2023 | 7.5 | 50 | NO | NO |
Signals from CVEs in this vendor scope (165 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Django.
Media articles that mention a CVE ID that affects a product developed by Django — matched by CVE ID, not by vendor name.