Django is a widely embedded Python web framework that, despite a narrow product footprint, reaches a very broad developer and deployment base across countless web applications. Its vulnerability disclosures center on input-handling and request-validation weaknesses characteristic of web frameworks—including cross-site scripting, cross-site request forgery, path traversal, and input-neutralization issues—that can propagate to any application built upon the framework. Defenders should prioritize Django security advisories as broadly applicable to their application inventory and treat framework updates as high-priority, since remediation depends on downstream application maintainers rebuilding; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Django Project over time
Signals from CVEs in this vendor scope (165 CVEs).
165 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34265CRITICAL An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a k | Jul 4, 2022 | 9.8 | 80 | NO | YES |
CVE-2021-35042CRITICAL Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application. | Jul 2, 2021 | 9.8 | 67 | NO | YES |
CVE-2020-7471CRITICAL Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer | Feb 3, 2020 | 9.8 | 67 | NO | NO |
CVE-2019-19844CRITICAL Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after cas | Dec 18, 2019 | 9.8 | 62 | NO | YES |
CVE-2025-64459CRITICAL An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q | Nov 5, 2025 | 9.1 | 58 | NO | YES |
CVE-2023-24580HIGH An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of p | Feb 15, 2023 | 7.5 | 57 | NO | NO |
CVE-2019-14234CRITICAL An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for djang | Aug 9, 2019 | 9.8 | 57 | NO | NO |
CVE-2026-1207HIGH An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to in | Feb 3, 2026 | 8.3 | 52 | NO | YES |
CVE-2022-23833HIGH An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infini | Feb 3, 2022 | 7.5 | 52 | NO | NO |
CVE-2023-23969HIGH In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a p | Feb 1, 2023 | 7.5 | 50 | NO | NO |
Signals from CVEs in this vendor scope (165 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Django Project.
Media articles that mention a CVE ID that affects a product developed by Django Project — matched by CVE ID, not by vendor name.