Django
Vendor:
First CVE: Jan 23, 2007 · Active for 19 years
159
Total CVEs
More Total CVEs than 80% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Django over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2007
19 years ago
Most Recent CVE
Jul 7, 2026
19 days ago
CVE Severity & Scoring
Django159 CVEs
54%
33%
8%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network107 (67.3%)
Unknown52 (32.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low95 (59.7%)
High12 (7.5%)
Unknown52 (32.7%)
User Interaction
None87 (54.7%)
Unknown52 (32.7%)
Required20 (12.6%)
Privileges Required
Low9 (5.7%)
High4 (2.5%)
None94 (59.1%)
Unknown52 (32.7%)
Top CVEs
Signals from CVEs in this product scope (159 CVEs).
159 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34265CRITICAL An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a k | Jul 4, 2022 | 9.8 | 80 | NO | YES |
CVE-2021-35042CRITICAL Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application. | Jul 2, 2021 | 9.8 | 67 | NO | YES |
CVE-2020-7471CRITICAL Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer | Feb 3, 2020 | 9.8 | 67 | NO | NO |
CVE-2019-19844CRITICAL Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after cas | Dec 18, 2019 | 9.8 | 60 | NO | YES |
CVE-2025-64459CRITICAL An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q | Nov 5, 2025 | 9.1 | 58 | NO | YES |
CVE-2023-24580HIGH An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of p | Feb 15, 2023 | 7.5 | 57 | NO | NO |
CVE-2019-14234CRITICAL An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for djang | Aug 9, 2019 | 9.8 | 57 | NO | NO |
CVE-2026-1207HIGH An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to in | Feb 3, 2026 | 8.3 | 54 | NO | YES |
CVE-2022-23833HIGH An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infini | Feb 3, 2022 | 7.5 | 52 | NO | NO |
CVE-2023-23969HIGH In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a p | Feb 1, 2023 | 7.5 | 50 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (159 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
3.8% of CVEs· Bottom 1%
ExploitDB
3 CVEs
1.9% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (159 CVEs).
Media Mentions
Signals from CVEs in this product scope (159 CVEs).
Top CNAs Publishing CVEs For Django
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.2 | 1 | 5.3 | 14.2% | 0 | 0 |
| 5.1 | 2 | 6.4 | 13.3% | 0 | 0 |
| 4.2 | 1 | 9.8 | 1.4% | 0 | 0 |
| 3.0 | 1 | 9.8 | 32.1% | 0 | 1 |
| 2.0.1 | 1 | 7.5 | 4.8% | 0 | 0 |
| 2.0 | 1 | 7.5 | 4.8% | 0 | 0 |
| 1.9.9 | 5 | 7.5 | 4.2% | 0 | 0 |
| 1.9.8 | 5 | 7.5 | 4.2% | 0 | 0 |
| 1.9.7 | 6 | 7.3 | 4.5% | 0 | 1 |
| 1.9.6 | 6 | 7.3 | 4.5% | 0 | 1 |
| 1.9.5 | 6 | 7.3 | 4.5% | 0 | 1 |
| 1.9.4 | 6 | 7.3 | 4.5% | 0 | 1 |
| 1.9.3 | 6 | 7.3 | 4.5% | 0 | 1 |
| 1.9.2 | 8 | 6.8 | 4.3% | 0 | 1 |
| 1.9.12 | 2 | 6.1 | 2.1% | 0 | 0 |
| 1.9.11 | 2 | 6.1 | 2.1% | 0 | 0 |
| 1.9.10 | 4 | 7.5 | 3.9% | 0 | 0 |
| 1.9.1 | 9 | 6.6 | 4.0% | 0 | 1 |
| 1.9.0 | 3 | 6.2 | 5.2% | 0 | 1 |
| 1.9 | 8 | 6.3 | 2.9% | 0 | 1 |