Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Django Project

First CVE: Jan 23, 2007Active for: 20 yearsTotal CVEs: 165

Django is a widely embedded Python web framework that, despite a narrow product footprint, reaches a very broad developer and deployment base across countless web applications. Its vulnerability disclosures center on input-handling and request-validation weaknesses characteristic of web frameworks—including cross-site scripting, cross-site request forgery, path traversal, and input-neutralization issues—that can propagate to any application built upon the framework. Defenders should prioritize Django security advisories as broadly applicable to their application inventory and treat framework updates as high-priority, since remediation depends on downstream application maintainers rebuilding; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
165
Total CVEs
More Total CVEs than 86% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Django Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2007
19 years ago
Most Recent CVE
Jul 7, 2026
18 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (165 CVEs).

165 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-34265CRITICAL
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a k
Jul 4, 20229.880NOYES
CVE-2021-35042CRITICAL
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
Jul 2, 20219.867NOYES
CVE-2020-7471CRITICAL
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer
Feb 3, 20209.867NONO
CVE-2019-19844CRITICAL
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after cas
Dec 18, 20199.862NOYES
CVE-2025-64459CRITICAL
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q
Nov 5, 20259.158NOYES
CVE-2023-24580HIGH
An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of p
Feb 15, 20237.557NONO
CVE-2019-14234CRITICAL
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for djang
Aug 9, 20199.857NONO
CVE-2026-1207HIGH
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to in
Feb 3, 20268.352NOYES
CVE-2022-23833HIGH
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infini
Feb 3, 20227.552NONO
CVE-2023-23969HIGH
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a p
Feb 1, 20237.550NONO
View all 165 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products165 CVEs
53%
35%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network111 (67.3%)
Unknown54 (32.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low98 (59.4%)
High13 (7.9%)
Unknown54 (32.7%)
User Interaction
None90 (54.5%)
Unknown54 (32.7%)
Required21 (12.7%)
Privileges Required
Low9 (5.5%)
High4 (2.4%)
None98 (59.4%)
Unknown54 (32.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (165 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
3.6% of CVEs· Bottom 1%
ExploitDB
3 CVEs
1.8% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Django Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Django Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Django Project's Products

View all 7 CNAs →

Top CWEs