Django is a widely adopted web-application framework maintained by the Django Project, whose relatively concentrated product portfolio — including the core framework, Channels for asynchronous support, and related utilities — underpins a large ecosystem of internet-facing applications across the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through application-layer weakness classes including SQL injection, cross-site scripting, improper input validation, path traversal, and resource-exhaustion conditions that reflect the framework's role in handling untrusted web requests and database interaction. A meaningful share of these disclosures acquire public exploit code, making Django advisories operationally urgent for organizations running exposed applications built with the framework. The concentration of exposure in the core framework and Channels means that patching one product can address risk across thousands of downstream applications, making this vendor's release cycle a critical dependency for web-application defenders. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Djangoproject over time
Signals from CVEs in this vendor scope (165 CVEs).
165 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34265CRITICAL An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a k | Jul 4, 2022 | 9.8 | 80 | NO | YES |
CVE-2021-35042CRITICAL Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application. | Jul 2, 2021 | 9.8 | 67 | NO | YES |
CVE-2020-7471CRITICAL Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer | Feb 3, 2020 | 9.8 | 67 | NO | NO |
CVE-2019-19844CRITICAL Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after cas | Dec 18, 2019 | 9.8 | 60 | NO | YES |
CVE-2025-64459CRITICAL An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q | Nov 5, 2025 | 9.1 | 58 | NO | YES |
CVE-2023-24580HIGH An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of p | Feb 15, 2023 | 7.5 | 57 | NO | NO |
CVE-2019-14234CRITICAL An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for djang | Aug 9, 2019 | 9.8 | 57 | NO | NO |
CVE-2026-1207HIGH An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to in | Feb 3, 2026 | 8.3 | 54 | NO | YES |
CVE-2022-23833HIGH An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infini | Feb 3, 2022 | 7.5 | 52 | NO | NO |
CVE-2023-23969HIGH In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a p | Feb 1, 2023 | 7.5 | 50 | NO | NO |
Signals from CVEs in this vendor scope (165 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Djangoproject.
Media articles that mention a CVE ID that affects a product developed by Djangoproject — matched by CVE ID, not by vendor name.