Django

Vendor:

First CVE: Jan 23, 2007 · Active for 19 years

159
Total CVEs
More Total CVEs than 80% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Django over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2007
19 years ago
Most Recent CVE
Jul 7, 2026
19 days ago

CVE Severity & Scoring

Django159 CVEs
All CVEs352,719 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network107 (67.3%)
Unknown52 (32.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low95 (59.7%)
High12 (7.5%)
Unknown52 (32.7%)
User Interaction
None87 (54.7%)
Unknown52 (32.7%)
Required20 (12.6%)
Privileges Required
Low9 (5.7%)
High4 (2.5%)
None94 (59.1%)
Unknown52 (32.7%)

Top CVEs

Signals from CVEs in this product scope (159 CVEs).

159 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a k
Jul 4, 20229.880NOYES
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
Jul 2, 20219.867NOYES
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer
Feb 3, 20209.867NONO
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after cas
Dec 18, 20199.860NOYES
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q
Nov 5, 20259.158NOYES
An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of p
Feb 15, 20237.557NONO
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for djang
Aug 9, 20199.857NONO
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to in
Feb 3, 20268.354NOYES
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infini
Feb 3, 20227.552NONO
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a p
Feb 1, 20237.550NONO

Exploit Exposure

Signals from CVEs in this product scope (159 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
3.8% of CVEs· Bottom 1%
ExploitDB
3 CVEs
1.9% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (159 CVEs).

Media Mentions

Signals from CVEs in this product scope (159 CVEs).

Top CNAs Publishing CVEs For Django

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.215.314.2%00
5.126.413.3%00
4.219.81.4%00
3.019.832.1%01
2.0.117.54.8%00
2.017.54.8%00
1.9.957.54.2%00
1.9.857.54.2%00
1.9.767.34.5%01
1.9.667.34.5%01
1.9.567.34.5%01
1.9.467.34.5%01
1.9.367.34.5%01
1.9.286.84.3%01
1.9.1226.12.1%00
1.9.1126.12.1%00
1.9.1047.53.9%00
1.9.196.64.0%01
1.9.036.25.2%01
1.986.32.9%01